SIFT: a low-overhead dynamic information flow tracking architecture for SMT processors

SIFT: a low-overhead dynamic information flow tracking architecture for SMT processors
复制标题

SIFT:用于 SMT 处理器的低开销动态信息流跟踪架构

DOI:
--
复制
发表时间:
2011
期刊:
ACM International Conference on Computing Frontiers
影响因子:
--
通讯作者:
Tameesh Suri
Tameesh Suri
中科院分区:
--
文献类型:
--
作者:
Meltem Ozsoy;D. Ponomarev;N. Abu;Tameesh Suri

文献摘要

被引文献

相似文献

动态信息流跟踪(DIFT)是一种功能强大的技术,可以保护未经修改的二进制文件免受缓冲区溢出和代码注入攻击等各种漏洞的影响。软件DIFT实现会导致非常高的性能开销,而全面的硬件实现会给微架构增加相当大的复杂性,使得芯片制造商不太可能采用它们。在本文中,我们提出了SIFT(基于SMT的DIFT),其中一个单独的线程执行污点传播和策略检查执行的SMT处理器的一个备用上下文中。然而,用于检查线程的指令是在流水线的提交阶段使用自包含的非关键路径逻辑在硬件中生成的。我们研究了对基本设计的几种优化,包括:(1)当主线程访问相应的数据时,从影子内存中预取污染数据;(2)优化污染指令的生成以删除不需要的指令。总之,在SPEC CPU 2006基准测试中,这些优化将SIFT的性能损失降低到26%,远低于以前提出的基于软件的DIFT方案的开销。为了证明SIFT的可行性,我们设计和合成一个核心与SIFT逻辑,并表明,面积开销的SIFT只有4.5%,指令生成可以在一个额外的周期在提交时间。
Dynamic Information Flow Tracking (DIFT) is a powerful technique that can protect unmodified binaries from a broad range of vulnerabilities such as buffer overflow and code injection attacks. Software DIFT implementations incur very high performance overhead, while comprehensive hardware implementations add substantial complexity to the microarchitecture, making it unlikely for chip manufacturers to adopt them. In this paper, we propose SIFT (SMT-based DIFT), where a separate thread performing taint propagation and policy checking is executed in a spare context of an SMT processor. However, the instructions for the checking thread are generated in hardware using self-contained off-the-critical path logic at the commit stage of the pipeline. We investigate several optimizations to the base design including: (1) Prefetching of the taint data from shadow memory when the corresponding data is accessed by the primary thread; (2) Optimizing the generation of the taint instructions to remove unneeded instructions. Together, these optimizations reduce the performance penalty of SIFT to 26% on SPEC CPU 2006 benchmarks--much lower than the overhead of previously proposed software-based DIFT schemes. To demonstrate the feasibility of SIFT, we design and synthesize a core with SIFT logic and show that the area overhead of SIFT is only 4.5% and that instruction generation can be performed in one additional cycle at commit time.