GARUDA: Designing Energy-Efficient Hardware Monitors From High-Level Policies for Secure Information Flow

GARUDA: Designing Energy-Efficient Hardware Monitors From High-Level Policies for Secure Information Flow
复制标题

GARUDA:根据安全信息流的高级策略设计节能硬件监视器

DOI:
--
复制
发表时间:
2018
影响因子:
2.9
通讯作者:
Avinash Karanth Kodi
Avinash Karanth Kodi
中科院分区:
计算机科学3区
文献类型:
--
作者:
Seaghan Sefton;Taiman Siddiqui;Nathaniel St. Amour;G. Stewart;Avinash Karanth Kodi

文献摘要

被引文献

相似文献

运行时监视器通过与不受信任的软件一起运行来检测嵌入式系统中的漏洞,以便在发生违反安全策略的行为时检测到它们,最好以最小的开销。先前的工作已经证明了对使用网格和基于标签的监视器实施的大部分静态安全策略的语言支持。然而,之前还没有提出将高级策略编译到模块化硬件监视器,从而可以以最小的功率实施各种安全策略。在本文中,我们提出了一种高级安全策略语言 GARUDA 以及从 GARUDA 到 Verilog 的编译器,它可以实现安全硬件运行时监视器的模块化构造和组合,以实现各种安全策略,包括软件故障隔离、安全控制流和通过污点跟踪的动态信息流。与硬件监视器检查所有指令的先前方法不同,我们的硬件监视器由安全策略按需激活,从而减少了能耗。我们在 Sniper(一个完整的系统多核模拟器)上进行实验,以评估我们迄今为止实施的安全策略的能量和性能权衡。这些策略在一系列 Splash-2 基准测试中进行了测试。
Runtime monitors detect vulnerabilities in embedded systems by running alongside untrusted software in order to detect violations of security policies as they occur, ideally with minimal overhead. Prior work has demonstrated language support for largely static security policies implemented using lattices and tag-based monitors. However, compiling high-level policies to modular hardware monitors that can implement a wide variety of security policies with minimal power has not been previously proposed. In this paper, we present a high-level security policy language, GARUDA, together with a compiler from GARUDA to Verilog, that enables the modular construction and composition of security hardware runtime monitors for a variety of security policies, including software fault isolation, secure control flow, and dynamic information flow via taint tracking. Unlike prior approaches in which the hardware monitors check all instructions, our hardware monitors are activated on-demand by the security policies which reduces the energy consumption. We perform experiments on Sniper, a full system multicore simulator, to evaluate the energy and performance tradeoffs of the security policies we have implemented so far. The policies are tested across a range of Splash-2 benchmarks.