Enhancing Security by Diversifying Instruction Sets

Enhancing Security by Diversifying Instruction Sets
复制标题

通过指令集多样化增强安全性

DOI:
--
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
A. Keromytis
A. Keromytis
中科院分区:
--
文献类型:
--
作者:
V. Kemerlis;Kanad Sinha;V. Pappas;S. Sethumadhavan;A. Keromytis

文献摘要

被引文献

相似文献

尽管关于硬件和软件的选择多种多样,但迄今为止,大量的计算机系统保持相同。这种趋势的典型例子是x86上的Windows和ARM上的Android。这种同质性,有时被称为“计算寡文化”,为当今高度网络化的世界中的恶意软件提供了肥沃的土壤。解决这个问题的一种方法是使系统多样化,这样攻击者就无法快速轻松地危害大量机器。例如,如果每个系统都有不同的伊萨,攻击者必须投入更多的时间来开发在每个系统表现上运行的漏洞。这并不是说每个单独的攻击变得更难,而是恶意软件的传播速度减慢了。此外,如果多样化的伊萨对攻击者保密,则利用的门槛会更高。在本文中,我们表明,系统多样化可以实现最低的硬件/软件接口,伊萨的多样性,几乎为零的性能开销。我们还描述了如何实际的开发和部署问题的多样化的系统可以很容易地处理流行的软件分布模型,如移动的应用程序商店模型的背景下。我们证明了我们的建议与OpenEQUIPMENT FPGA原型。
Despite the variety of choices regarding hardware and software, to date a large number of computer systems remain identical. Characteristic examples of this trend are Windows on x86 and Android on ARM. This homogeneity, sometimes referred to as “computing oligoculture", provides a fertile ground for malware in the highly networked world of today. One way to counter this problem is to diversify systems so that attackers cannot quickly and easily compromise a large number of machines. For instance, if each system has a different ISA, the attacker has to invest more time in developing exploits that run on every system manifestation. It is not that each individual attack gets harder, but the spread of malware slows down. Further, if the diversified ISA is kept secret from the attacker, the bar for exploitation is raised even higher. In this paper, we show that system diversification can be realized by enabling diversity at the lowest hardware/software interface, the ISA, with almost zero performance overhead. We also describe how practical development and deployment problems of diversified systems can be handled easily in the context of popular software distrbution models, such as the mobile app store model. We demonstrate our proposal with an OpenSPARC FPGA prototype.