TZSlicer: Security-aware dynamic program slicing for hardware isolation

TZSlicer: Security-aware dynamic program slicing for hardware isolation
复制标题

TZSlicer:用于硬件隔离的安全感知动态程序切片

DOI:
--
复制
发表时间:
2018
期刊:
IEEE International Symposium on Hardware Oriented Security and Trust
影响因子:
--
通讯作者:
Sheng Wei
Sheng Wei
中科院分区:
--
文献类型:
--
作者:
Mengmei Ye;Jonathan M. Sherman;W. Srisa;Sheng Wei

文献摘要

被引文献

相似文献

为了解决与信息泄漏有关的安全问题,微处理器设计人员和ARM和英特尔等制造商已经引入了基于硬件隔离的技术,以支持安全的软件执行。但是,利用此类技术通常需要重大努力来设计新的应用程序或重构现有应用程序以遵守使用协议。开发人员还需要明确区分可以操纵敏感数据并将其重新安置到安全执行环境的代码部分。这些过程可能是费力且容易出错的,因为过度保护可能导致应用程序性能差和资源较高,并且保护不足可能会导致可利用的安全性漏洞。在本文中,我们介绍了TZSlicer,这是一个框架,以自动识别必须根据开发人员提供的敏感变量列表进行保护的代码。 TZSlicer自动标识可以处理敏感数据,从原始程序中提取这些部分的代码部分,并在原始和提取的代码部分中创建线束,以便它们可以相互接口。我们开发了TZSlicer的原型,以支持在功能,代码块和代码行级别上C程序切片。此外,我们确定了通过应用循环展开和可变重命名的优化机会,以改善TZSlicer的上下文切换开销。我们使用七个现实世界程序评估了TZSlicer,评估结果表明TZSlicer可以有效地保护敏感数据,而不会产生大量的运行时和资源使用费用。
To address security issues related to information leakage, microprocessor designers and manufacturers such as ARM and Intel have introduced hardware isolation-based technologies to support secure software execution. However, utilizing such technologies often requires significant efforts to design new applications or refactor existing applications to adhere to the usage protocols. Developers also need to clearly distinguish code sections that can manipulate sensitive data and relocate them to the secure execution environment. These processes can be laborious and error-prone, since over-protection can result in poor application performance and high resource usage, and under-protection may cause exploitable security vulnerabilities. In this paper, we introduce TZSlicer, a framework to automatically identify code that must be protected based on a sensitive variable list provided by developers. TZSlicer automatically identifies code sections that can process sensitive data, extracts those sections from the original program, and creates harness in the original and extracted code sections so that they can interface with each other. We develop a prototype of TZSlicer to support slicing of C programs at function, code block, and code line levels. Also, we identify optimization opportunities to improve the context switching overhead of TZSlicer via applying loop unrolling and variable renaming. We evaluate TZSlicer using seven real-world programs, and the evaluation results indicate that TZSlicer is effective in protecting sensitive data without incurring significant runtime and resource usage overheads.