Leaky Buddies: Cross-Component Covert Channels on Integrated CPU-GPU Systems

Leaky Buddies: Cross-Component Covert Channels on Integrated CPU-GPU Systems
复制标题

DOI:
10.1109/isca52012.2021.00080
复制
发表时间:
2020-11
期刊:
2021 ACM/IEEE 48th Annual International Symposium on Computer Architecture (ISCA)
影响因子:
--
通讯作者:
Sankha Baran Dutta;Hoda Naghibijouybari;N. Abu-Ghazaleh;A. Márquez;K. Barker
Sankha Baran Dutta;Hoda Naghibijouybari;N. Abu-Ghazaleh;A. Márquez;K. Barker
中科院分区:
其他
文献类型:
--
作者:
Sankha Baran Dutta;Hoda Naghibijouybari;N. Abu-Ghazaleh;A. Márquez;K. Barker

文献摘要

相似文献

图形处理单元(GPU)是当今计算平台范围内普遍使用的组件,从手机和平板电脑到个人电脑,再到高端服务器级平台。随着图形和视频工作负载的重要性日益增加,最近的处理器与集成在同一芯片上的GPU设备一起发货。集成的GPU与CPU共享一些资源,因此,存在从GPU到CPU的微架构攻击的可能性,反之亦然。我们考虑了来自共享微架构组件(如缓存)或通过共享争用域(例如,公共汽车)。我们说明了这两种类型的通道,通过开发两个可靠的隐蔽通道攻击。第一个隐蔽通道使用英特尔集成GPU架构中的共享LLC缓存。第二个是基于竞争的通道,目标是将CPU和GPU连接到LLC的环形总线。这是第一个跨越组件边界(GPU到CPU,反之亦然)的微架构攻击。跨组件通道引入了许多新的挑战,我们必须克服,因为它们发生在使用不同计算模型的异构组件之间,并使用非对称内存层次结构互连。我们还利用GPU并行性来增加通信的带宽,即使不依赖于一个共同的时钟。基于LLC的信道以2%的低错误率实现120 kbps的带宽,而基于竞争的信道以0.8%的错误率提供高达400 kbps的带宽。我们还演示了一个概念验证的素数和探测侧通道攻击,探测从GPU的完整LLC。
Graphics Processing Units (GPUs) are ubiquitous components used across the range of today’s computing platforms, from phones and tablets, through personal computers, to high-end server class platforms. With the increasing importance of graphics and video workloads, recent processors are shipped with GPU devices that are integrated on the same chip. Integrated GPUs share some resources with the CPU and as a result, there is a potential for microarchitectural attacks from the GPU to the CPU or vice versa. We consider the potential for covert channel attacks that arise either from shared microarchitectural components (such as caches) or through shared contention domains (e.g., shared buses). We illustrate these two types of channels by developing two reliable covert channel attacks. The first covert channel uses the shared LLC cache in Intel’s integrated GPU architectures. The second is a contention based channel targeting the ring bus connecting the CPU and GPU to the LLC. This is the first demonstrated microarchitectural attack crossing the component boundary (GPU to CPU or vice versa). Cross-component channels introduce a number of new challenges that we had to overcome since they occur across heterogeneous components that use different computation models and are interconnected using asymmetric memory hierarchies. We also exploit GPU parallelism to increase the bandwidth of the communication, even without relying on a common clock. The LLC based channel achieves a bandwidth of 120 kbps with a low error rate of 2%, while the contention based channel delivers up to 400 kbps with a 0.8% error rate. We also demonstrate a proof-of-concept prime-and-probe side channel attack that probes the full LLC from the GPU.