CRII: SaTC: Secure Branch Predictors for High Performance Processors
CRII: SaTC: Secure Branch Predictors for High Performance Processors
批准号:
1850365
负责人:
Dmitry Evtyushkin
金额:
$17.5万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-07-01 至 2022-06-30
中文摘要
分支预测器(BP)是当今处理器中关键的性能改进机制之一。最近的研究表明,它可以用来发起强大的攻击,如侧信道和基于投机执行的攻击。这些攻击允许对手窃取敏感数据并破坏计算机系统。该项目调查了现有BP设计带来的安全威胁,并开发了新的安全设计,在不显著降低性能的情况下阻止与BP相关的攻击。首先,该项目通过共享BP数据结构解决敏感数据泄露问题。它开发了一种安全共享机制,允许BP结构共享,同时防止危险碰撞。其次,该项目解决了由错误预测的分支指令引起的推测性执行威胁。这是通过重新设计处理器的推测执行组件来实现的,方法是添加推测指令执行的限制,并缓存关键数据以防止剧烈的性能损失。第三,该项目开发了一个新的评估框架,用于评估和比较新的和现有的分支预测器设计的安全性和性能特性。硬件安全漏洞影响着全球数十亿台计算机。该项目旨在通过设计安全分支预测器来提高计算机硬件的安全性,并阻止已知和未来的攻击。因此,未来计算机的安全性将得到提高,对社会产生积极的影响。这个项目的发现被用于课程开发。这个项目积极地让研究生参与研究。该项目产生的数据、代码和其他研究工件将存储在本地的William and Mary机器上,并备份到内部网络存储系统。工具和数据样本将在项目网站上提供:http://www.cs.wm.edu/~dmitry/safebp/。在此项目中产生的所有数据将在项目期间和至少另外两年保存。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Branch predictor (BP) is one of the key performance improvement mechanisms in today's processors. Recent studies demonstrate that it can be used to initiate powerful attacks such as side-channel and speculative execution-based attacks. These attacks allow adversaries to steal sensitive data and compromise computer systems. This project investigates security threats introduced by existing BP designs and develops new safe designs to stop BP-related attacks without significantly degrading the performance. First, the project addresses the problem of sensitive data leakage through shared BP data structures. It develops a safe sharing mechanism which permits BP structure sharing while simultaneously preventing dangerous collisions. Second, the project addresses the speculative execution threats caused by incorrectly predicted branch instructions. This is achieved by redesigning speculative execution components of the processor by adding restrictions on speculative instruction execution and caching critical data to prevent drastic performance losses. Third, the project develops a novel evaluation framework that is used to evaluate and compare security and performance properties of new and existing branch predictor designs. Hardware security vulnerabilities affect billions of computers worldwide. This project intends to improve the security of computer hardware and disallow both known and future attacks by designing safe branch predictors. As a result, security of future computers will be improved, making a positive impact on society. Discoveries from this project are used in curriculum development. The project actively involves graduate students into research. Data, code and other research artifacts generated by this project will be stored locally at William and Mary machines and backed up to an in-house network storage system. Tools and data samples will be available at the project website: http://www.cs.wm.edu/~dmitry/safebp/. All data generated during this project will be kept for the duration of the project and at least two additional years.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1109/dsn53405.2022.00023
发表时间:
2021-08
期刊:
2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
作者:
[Zhang Tao;Timothy Lesch;Kenneth Koltermann;Dmitry Evtyushkin]
通讯作者:
Zhang Tao;Timothy Lesch;Kenneth Koltermann;Dmitry Evtyushkin
Exploring Branch Predictors for Constructing Transient Execution Trojans
探索用于构建瞬态执行木马的分支预测器
DOI:
10.1145/3373376.3378526
发表时间:
2020
期刊:
ASPLOS '20: Proceedings of the Twenty-Fifth International Conference on Architectural Support for Programming Languages and Operating Systems
影响因子:
--
作者:
[Zhang, Tao, Koltermann, Kenneth, Evtyushkin, Dmitry]
通讯作者:
Evtyushkin, Dmitry
CAREER: Weird Machines: a New Foundation for Advancing Microarchitectural Security
-
批准号:2145635
-
项目类别:Continuing Grant
-
资助金额:$55.44万
-
财政年份:2022
-
负责人:Dmitry Evtyushkin
-
依托单位:
海外基金