SPECS: A Lightweight Runtime Mechanism for Protecting Software from Security-Critical Processor Bugs

SPECS: A Lightweight Runtime Mechanism for Protecting Software from Security-Critical Processor Bugs
复制标题

规格:一种轻量级运行时机制,用于保护软件免受安全关键处理器错误的影响

DOI:
10.1145/2694344.2694366
复制
发表时间:
2015
期刊:
Proceedings of the Twentieth International Conference on Architectural Support for Programming Languages and Operating Systems
影响因子:
--
通讯作者:
Jonathan M. Smith
Jonathan M. Smith
中科院分区:
--
文献类型:
--
作者:
Matthew Hicks;C. Sturton;Samuel T. King;Jonathan M. Smith

文献摘要

被引文献

相似文献

处理器实现勘误表仍然是一个问题,更糟糕的是,这些错误的子集是安全关键的。我们对最近商业处理器的7年勘误表进行了分类,以了解此问题的严重性和严重性,并发现在分析的301个勘误表中,有28个是安全关键的。我们提出了一个低开销的解决方案,这个问题的可靠性关键的代理ER- RATA捕捉系统(SPECS)。SPECS采用动态验证策略,通过将保护限制为仅对安全关键的处理器状态进行轻量化。作为一个概念验证,我们实现了一个硬件原型的SPECS在一个开源的处理器。使用这个原型,我们评估SPECS对一组14个错误的启发类型的安全关键的勘误表,我们发现在分类阶段。评估结果表明,SPECS是86%的有效防御部署时,只使用ISA级状态,产生小于5%的面积和功耗开销,并没有软件运行时开销。
Processor implementation errata remain a problem, and worse, a subset of these bugs are security-critical. We classified 7 years of errata from recent commercial processors to understand the magnitude and severity of this problem, and found that of 301 errata analyzed, 28 are security-critical. We propose the SECURITY-CRITICAL PROCESSOR ER- RATA CATCHING SYSTEM (SPECS) as a low-overhead solution to this problem. SPECS employs a dynamic verification strategy that is made lightweight by limiting protection to only security-critical processor state. As a proof-of- concept, we implement a hardware prototype of SPECS in an open source processor. Using this prototype, we evaluate SPECS against a set of 14 bugs inspired by the types of security-critical errata we discovered in the classification phase. The evaluation shows that SPECS is 86% effective as a defense when deployed using only ISA-level state; incurs less than 5% area and power overhead; and has no software run-time overhead.