Detecting Malicious Attacks Exploiting Hardware Vulnerabilities Using Performance Counters

Detecting Malicious Attacks Exploiting Hardware Vulnerabilities Using Performance Counters
复制标题

DOI:
10.1109/compsac.2019.00090
复制
发表时间:
2019-07
期刊:
2019 IEEE 43rd Annual Computer Software and Applications Conference (COMPSAC)
影响因子:
--
通讯作者:
Congmiao Li;J. Gaudiot
Congmiao Li;J. Gaudiot
中科院分区:
其他
文献类型:
--
作者:
Congmiao Li;J. Gaudiot

文献摘要

被引文献

相似文献

在过去的几十年中,计算机设计的主要目标是提高性能并降低成本,能源消耗和规模,而安全性仍然是次要问题。同时,随着互联网连接的设备的数量,从个人智能嵌入式系统到大型云服务器,恶意攻击已迅速发展。传统的防病毒软件无法跟上这些攻击的发生率的增加,尤其是针对针对硬件设计漏洞的利用。例如,随着DRAM工艺技术的扩展,DRAM细胞可以更轻松地相互作用。例如,在Rowhammer攻击中,可以通过DRAM阅读同一行来损坏附近行中的数据。当Rowhammer利用计算机硬件弱点时,没有软件补丁可以完全解决问题。同样,最近报道的攻击幽灵也没有有效的软件减轻措施。该攻击利用微体系设计漏洞通过侧渠道泄漏受保护的数据。通常,完全修复了硬件级别的漏洞将需要重新设计无法备份的硬件。在本文中,我们证明,通过监视微体系事件的偏差,例如缓存失误,现有CPU性能计数器的分支错误预测,可以在运行时有效地检测到的硬件级攻击,例如Rowhammer和Specter机器学习分类器。
Over the past decades, the major objectives of computer design have been to improve performance and to reduce cost, energy consumption, and size, while security has remained a secondary concern. Meanwhile, malicious attacks have rapidly grown as the number of Internet-connected devices, ranging from personal smart embedded systems to large cloud servers, have been increasing. Traditional antivirus software cannot keep up with the increasing incidence of these attacks, especially for exploits targeting hardware design vulnerabilities. For example, as DRAM process technology scales down, it becomes easier for DRAM cells to electrically interact with each other. For instance, in Rowhammer attacks, it is possible to corrupt data in nearby rows by reading the same row in DRAM. As Rowhammer exploits a computer hardware weakness, no software patch can completely fix the problem. Similarly, there is no efficient software mitigation to the recently reported attack Spectre. The attack exploits microarchitectural design vulnerabilities to leak protected data through side channels. In general, completely fixing hardware-level vulnerabilities would require a redesign of the hardware which cannot be backported. In this paper, we demonstrate that by monitoring deviations in microarchitectural events such as cache misses, branch mispredictions from existing CPU performance counters, hardware-level attacks such as Rowhammer and Spectre can be efficiently detected during runtime with promising accuracy and reasonable performance overhead using various machine learning classifiers.