课题基金 / 基金详情

CAREER: A Quantitative Framework for Analyzing and Mitigating Microarchitectural Side Channels

CAREER: A Quantitative Framework for Analyzing and Mitigating Microarchitectural Side Channels
职业:分析和缓解微架构侧通道的定量框架
批准号:
2046359
负责人:
Mengjia Yan
金额:
$51.2万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-02-15 至 2026-01-31

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Microarchitectural side-channel attacks that breach processor security and broadly affect computer systems have become one of the major security threats. Those attacks exploit the fact that software, when executing on modern processors, leaves traces on microarchitecture structures, and the traces can reveal private user information. Current defenses against microarchitectural side-channel attacks aim to reduce information leakage but unavoidably incur performance overhead, because they lose the capability of fully exploiting performance optimizations in computing systems. This project will develop a toolset to enable productive trade-offs between security and performance in mitigating microarchitectural side-channel attacks.The project tackles fundamental research problems in designing, evaluating, and using channel obfuscation techniques. The technical approach is to frame microarchitectural side channels, a computer architecture security problem, as a communication problem, and constructs quantitative channel models for microarchitectural structures. The first project thrust constructs the quantitative channel models, characterizing and quantifying the impacts of complex hardware events. The second thrust uses the channel models to measure the information leakage of the applications running on obfuscated architectures. The third thrust explores co-design channel obfuscation techniques with existing mitigation and detection solutions.The project will develop a toolset to mitigate microarchitectural side-channel attacks efficiently. The toolset can benefit a wide range of people who design, manage, and use computing systems, including computer architects, system administrators, and software developers. In addition, this project will initiate an effort on course offerings in the area of hardware security at Massachusetts of Technology. This project will also offer research opportunities to undergraduate students and under-represented minorities. This project will store all publications, code, and data-sets on public-facing websites, hosted at Massachusetts of Technology for at least 3 years after the end of the project. This information will be made available via commercial websites. Links to these websites will be mirrored at http://people.csail.mit.edu/mengjia/projects.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3623652.3623669
发表时间: 2023-10
期刊: Proceedings of the 12th International Workshop on Hardware and Architectural Support for Security and Privacy
影响因子: --
作者: [William Liu;Joseph Ravichandran;Mengjia Yan]
通讯作者: William Liu;Joseph Ravichandran;Mengjia Yan
Pensieve: Microarchitectural Modeling for Security Evaluation
Pensieve:用于安全评估的微架构建模
DOI: 10.1145/3579371.3589094
发表时间: 2023
期刊: ACM
影响因子: --
作者: [Yang, Yuheng, Bourgeat, Thomas, Lau, Stella, Yan, Mengjia]
通讯作者: Yan, Mengjia
Metior: A Comprehensive Model to Evaluate Obfuscating Side-Channel Defense Schemes
Metior:评估混淆侧通道防御方案的综合模型
DOI: 10.1145/3579371.3589073
发表时间: 2023
期刊: 49th Annual International Symposium on Computer Architecture
影响因子: --
作者: [Deutsch, Peter W., Na, Weon Taek, Bourgeat, Thomas, Emer, Joel S., Yan, Mengjia]
通讯作者: Yan, Mengjia
There’s Always a Bigger Fish: A Clarifying Analysis of a Machine-Learning-Assisted Side-Channel Attack
总有更大的鱼:机器学习辅助侧通道攻击的澄清分析
DOI: 10.1109/mm.2023.3273457
发表时间: 2023
期刊: IEEE Micro
影响因子: 3.6
作者: [Cook, Jack, Drean, Jules, Behrens, Jonathan, Yan, Mengjia]
通讯作者: Yan, Mengjia
海外基金