Speculation Invariance (InvarSpec): Faster Safe Execution Through Program Analysis

Speculation Invariance (InvarSpec): Faster Safe Execution Through Program Analysis
复制标题

推测不变性 (InvarSpec):通过程序分析加快安全执行速度

DOI:
10.1109/micro50266.2020.00094
复制
发表时间:
2020
期刊:
2020 53rd Annual IEEE/ACM International Symposium on Microarchitecture (MICRO)
影响因子:
--
通讯作者:
J. Torrellas
J. Torrellas
中科院分区:
--
文献类型:
--
作者:
Zirui Neil Zhao;Houxiang Ji;Mengjia Yan;Jiyong Yu;Christopher W. Fletcher;Adam Morrison;D. Marinov;J. Torrellas

文献摘要

参考文献

被引文献

相似文献

针对投机性执行攻击的许多基于硬件的防御方案使用特殊的机制来保护指令,并在本文中提出指令时提取机制,我们观察到投机性指令有时会在不形式上变成不变性。 。他们没有保护,我们改善了防御计划的性能,而无需更改其安全性。在i-e。的旧说明中,那些不会阻止我在运行时成为投机的指示,invarspec Micro-Architecture加载了此信息,并使用它来确定何时可以发出投机性指令而无需保护在组合合作编译器和硬件机制的投机性执行方案中,我们的评估有效地减少了硬件防御方案的执行开销。 108.2%的延迟失误从39.5%到24.4%,而Invisispec的延迟失误为15.4%至10.9%。
Many hardware-based defense schemes against speculative execution attacks use special mechanisms to protect instructions while speculative, and lift the mechanisms when the instructions turn non-speculative. In this paper, we observe that speculative instructions can sometimes become Speculation Invariant before turning non-speculative. Speculation invariance means that (i) whether the instruction will execute and (ii) the instruction’s operands are not a function of speculative state. Hence, we propose to lift the protection mechanisms on these instructions early, when they become speculation invariant, and issue them without protection. As a result, we improve the performance of the defense schemes without changing their security properties.To exploit speculation invariance, we present the InvarSpec framework. InvarSpec includes a program analysis pass that identifies, for each relevant instruction i, the set of older instructions that are Safe for i—i.e., those that do not prevent i from becoming speculation invariant. At runtime, the InvarSpec micro-architecture loads this information and uses it to determine when speculative instructions can be issued without protection. InvarSpec is one of the first defense schemes for speculative execution that combines cooperative compiler and hardware mechanisms. Our evaluation shows that InvarSpec effectively reduces the execution overhead of hardware defense schemes. For example, on SPEC17, it reduces the average execution overhead of fence protections from 195.3% to 108.2%, of Delay-On-Miss from 39.5% to 24.4%, and of InvisiSpec from 15.4% to 10.9%.
DOI: 10.1109/isca45697.2020.00022
发表时间: 2019-11
期刊: 2020 ACM/IEEE 47th Annual International Symposium on Computer Architecture (ISCA)
影响因子: --
作者:
S. Ainsworth;Timothy M. Jones
通讯作者: S. Ainsworth;Timothy M. Jones