Siloz: Leveraging DRAM Isolation Domains to Prevent Inter-VM Rowhammer

Siloz: Leveraging DRAM Isolation Domains to Prevent Inter-VM Rowhammer
复制标题

DOI:
10.1145/3600006.3613143
复制
发表时间:
2023-10
期刊:
Proceedings of the 29th Symposium on Operating Systems Principles
影响因子:
--
通讯作者:
Kevin Loughlin;Jonah Rosenblum;S. Saroiu;A. Wolman;Dimitrios Skarlatos;Baris Kasikci
Kevin Loughlin;Jonah Rosenblum;S. Saroiu;A. Wolman;Dimitrios Skarlatos;Baris Kasikci
中科院分区:
其他
文献类型:
--
作者:
Kevin Loughlin;Jonah Rosenblum;S. Saroiu;A. Wolman;Dimitrios Skarlatos;Baris Kasikci

文献摘要

被引文献

相似文献

如今的云动态随机存取存储器(DRAM)缺乏强大的隔离原语,“行锤击”(Rowhammer)导致的比特翻转问题凸显了这一点。鉴于以下两点,“行锤击”对云安全与可靠性构成的威胁日益增大:其一,商用及恶意工作负载中的DRAM激活率已然超过“行锤击”阈值;其二,在更新的DRAM中,这些阈值还在不断降低。已部署的硬件缓解措施依旧存在漏洞,这使得云服务提供商转而寻求软件防御手段。然而,现有的防御措施要么会带来高昂的性能或内存开销,要么存在显著的防护漏洞。因此,我们推出了Siloz,这是一款管理程序,它将子阵列组用作DRAM隔离域,从而能够有效地防范虚拟机(VM)间的“行锤击”攻击。Siloz基于以下两点认知:(a)“行锤击”只能翻转位于同一子阵列内DRAM行中的比特,而无法跨子阵列翻转;(b)虚拟机可以被隔离到子阵列组中,且不会牺牲内存库级并行性(这是DRAM性能的关键要素)。因此,Siloz通过将每个虚拟机及主机的数据置于专用子阵列组中,来防止虚拟机间的比特翻转。为进一步确保虚拟机无法逃离其分配的子阵列组,Siloz还为扩展页表(EPT)提供完整性保护。我们的研究表明,Siloz的实现在各类云工作负载、SPEC CPU 2017以及PARSEC 3.0测试中,对平均性能的影响微乎其微(与基线Linux/KVM相比,性能波动在±0.5%以内)。
Today's cloud DRAM lacks strong isolation primitives, highlighted by Rowhammer bit flips. Rowhammer poses an increasing threat to cloud security/reliability, given (1) DRAM activation rates in commodity and malicious workloads already exceed Rowhammer thresholds, and (2) thresholds are decreasing in newer DRAM. Deployed hardware mitigations remain vulnerable, turning cloud providers toward software defenses. However, existing defenses incur high performance or memory overhead or contain significant protection gaps. Accordingly, we introduce Siloz, a hypervisor that uses subarray groups as DRAM isolation domains to enable efficient protection against inter-VM Rowhammer. Siloz exploits the insights that (a) Rowhammer can only flip bits in DRAM rows located in the same subarray---not across subarrays---and (b) VMs can be isolated to groups of subarrays without sacrificing bank-level parallelism, a key component of DRAM performance. Siloz thus prevents inter-VM bit flips by placing each VM's and the host's data into private subarray groups. To additionally ensure that a VM cannot escape its provisioned subarray group(s), Siloz provides integrity protection for extended page tables (EPTs). We show that Siloz's implementation has negligible effect on average performance across various cloud workloads, SPEC CPU 2017, and PARSEC 3.0 (within ±0.5% of baseline Linux/KVM).