Evaluating security requirements in a general-purpose processor by combining assertion checkers with code coverage

Evaluating security requirements in a general-purpose processor by combining assertion checkers with code coverage
复制标题

通过将断言检查器与代码覆盖率相结合来评估通用处理器中的安全要求

DOI:
10.1109/hst.2012.6224318
复制
发表时间:
2012
期刊:
2012 IEEE International Symposium on Hardware-Oriented Security and Trust
影响因子:
--
通讯作者:
T. Levin
T. Levin
中科院分区:
--
文献类型:
--
作者:
Michael Bilzor;Ted Huffmire;C. Irvine;T. Levin

文献摘要

被引文献

相似文献

硬件中的恶意包含问题是一种新兴的威胁,检测它们是一项艰巨的挑战。在这项研究中,我们提高了现有的方法,创建基于断言的动态检查器,并演示了如何行为的安全要求,可以从处理器的架构规范,然后转换成安全检查器的处理器的设计的一部分。本研究的新贡献是:-我们证明了使用一组断言的方法,来自架构规范,在一个全面的开源通用处理器设计,称为OpenRISC。以前的工作在玩具处理器设计上只使用了一个断言。- 我们演示了使用我们的检查器生成器工具,称为psl 2 hdl,这是为这项研究。- 我们说明了该方法如何可以与代码覆盖技术,以检测恶意夹杂物或大大缩小搜索使用罕见事件触发器的恶意夹杂物。
The problem of malicious inclusions in hardware is an emerging threat, and detecting them is a difficult challenge. In this research, we enhance an existing method for creating assertion-based dynamic checkers, and demonstrate how behavioral security requirements can be derived from a processor's architectural specification, then converted into security checkers that are part of the processor's design. The novel contributions of this research are: - We demonstrate the method using a set of assertions, derived from the architectural specification, on a full-scale open-source general-purpose processor design, called OpenRISC. Previous work used only a single assertion on a toy processor design. - We demonstrate the use of our checker-generator tool, called psl2hdl, which was created for this research. - We illustrate how the method can be used in concert with code coverage techniques, to either detect malicious inclusions or greatly narrow the search for malicious inclusions that use rare-event triggers.