CAREER: Weird Machines: a New Foundation for Advancing Microarchitectural Security

职业:奇怪的机器:推进微架构安全的新基础

基本信息

  • 批准号:
    2145635
  • 负责人:
  • 金额:
    $ 55.44万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2022
  • 资助国家:
    美国
  • 起止时间:
    2022-07-01 至 2027-06-30
  • 项目状态:
    未结题

项目摘要

The Central Processing Unit (CPU) is a key element of a typical computing system. To improve performance, microarchitecture (MA) of modern CPUs include multiple sub-systems with complex internal state and functionality. While improving performance, these sub-systems often trigger unexpected observable side-effects which are known to enable attacks resulting in sensitive data leakage. The ever-growing complexity of CPU components and the complex nature of the cross-component interaction make it challenging to detect such effects. This CAREER project utilizes the concept of weird machines, a theoretical framework that enables analyzing security vulnerabilities via the theory of computation. According to this concept, vulnerabilities create a new computational model within the original computational entity with properties not intended by its design. Previously, weird machines were mostly used to study software systems. This CAREER project utilizes the concept of weird machines to systematically identify MA side effects and explore how they can be used by a potential attacker. The investigator has discovered that the interaction of MA components creates a new programmable computational model within the CPU microarchitecture that is invisible to existing methods of analysis. At the same time, it can be used to hide malicious activities or to trigger unexpected systems behaviors. The project’s novelties are 1) using the concept of weird machines to study MA security, 2) exploring computational capabilities of MA side effects, 3) investigating use cases for the new model of computation. The project's broader significance and importance are 1) improving the understanding of the attack surface in modern computer systems, 2) establishing a new approach for identifying and documenting MA side effects to be used for research and education.This CAREER project is centered on three main objectives. First, known MA side-effects are documented as weird machine primitives, followed by an automated search for new side-effects. Second, the computational capabilities and practicality of MA weird machines are investigated including programmability of such machines and methods to improve their reliability. In addition, the project explores the feasibility of constructing a universal MA weird machine capable of performing arbitrary computations. Third, the established MA weird machines framework is applied to study known types of MA attacks, such as side channels, enabling discovery of new attack variants.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
中央处理单元(CPU)是典型计算系统的关键元件。为了提高性能,现代CPU的微体系结构(MA)包括具有复杂内部状态和功能的多个子系统。在提高性能的同时,这些子系统通常会触发意想不到的可观察到的副作用,已知这些副作用会导致敏感数据泄漏的攻击。CPU组件的复杂性不断增加,跨组件交互的复杂性使得检测此类影响具有挑战性。这个CAREER项目利用了怪异机器的概念,这是一个理论框架,可以通过计算理论分析安全漏洞。根据这一概念,漏洞在原始计算实体中创建了一个新的计算模型,其属性不是其设计的目的。以前,奇怪的机器大多用于研究软件系统。这个CAREER项目利用怪异机器的概念来系统地识别MA的副作用,并探索它们如何被潜在的攻击者使用。研究人员发现,MA组件的相互作用在CPU微架构中创建了一个新的可编程计算模型,这是现有分析方法所不可见的。与此同时,它可以用来隐藏恶意活动或触发意外的系统行为。该项目的新颖之处在于:1)使用怪异机器的概念来研究MA安全性,2)探索MA副作用的计算能力,3)调查新计算模型的用例。该项目的更广泛的意义和重要性是1)提高对现代计算机系统中攻击面的理解,2)建立一种新的方法来识别和记录MA副作用,用于研究和教育。这个CAREER项目围绕三个主要目标。首先,已知的MA副作用被记录为奇怪的机器原语,然后自动搜索新的副作用。其次,研究了MA怪机器的计算能力和实用性,包括这类机器的可编程性和提高其可靠性的方法。此外,该项目还探索了构建能够执行任意计算的通用MA怪异机器的可行性。第三,已建立的MA怪异机器框架被应用于研究已知类型的MA攻击,如侧通道,从而能够发现新的攻击变种。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Dmitry Evtyushkin其他文献

How the spectre and meltdown hacks really worked
幽灵和崩溃黑客是如何真正起作用的
  • DOI:
    10.1109/mspec.2019.8651934
  • 发表时间:
    2019
  • 期刊:
  • 影响因子:
    3.1
  • 作者:
    N. Abu;D. Ponomarev;Dmitry Evtyushkin
  • 通讯作者:
    Dmitry Evtyushkin
Hardening extended memory access control schemes with self-verified address spaces
使用自验证地址空间强化扩展内存访问控制方案
Covert Channels through Random Number Generator: Mechanisms, Capacity Estimation and Mitigations
通过随机数生成器的隐蔽通道:机制、容量估计和缓解措施
Covert channels through branch predictors: a feasibility study
通过分支预测器的隐蔽通道:可行性研究

Dmitry Evtyushkin的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Dmitry Evtyushkin', 18)}}的其他基金

CRII: SaTC: Secure Branch Predictors for High Performance Processors
CRII:SaTC:高性能处理器的安全分支预测器
  • 批准号:
    1850365
  • 财政年份:
    2019
  • 资助金额:
    $ 55.44万
  • 项目类别:
    Standard Grant

相似海外基金

UN-WEIRDなポジティブ心理学的概念の探求と個人最適化PPIsの開発
UN-WEIRD 积极心理学概念的探索和个体优化 PPI 的开发
  • 批准号:
    24K00491
  • 财政年份:
    2024
  • 资助金额:
    $ 55.44万
  • 项目类别:
    Grant-in-Aid for Scientific Research (B)
Proposed research title(s) History, 'Weird Time', and the Subterranean in Britain, c. 1100-1400
拟议的研究标题历史、“奇怪的时间”和英国的地下,c。
  • 批准号:
    2908501
  • 财政年份:
    2023
  • 资助金额:
    $ 55.44万
  • 项目类别:
    Studentship
The 'Confrontational Escapism' of the New Weird: Reading Challenging Fiction in Online Spaces
新怪异的“对抗性逃避现实”:在网络空间中阅读具有挑战性的小说
  • 批准号:
    2885935
  • 财政年份:
    2023
  • 资助金额:
    $ 55.44万
  • 项目类别:
    Studentship
Weird homemaking: precarious geographies of home in British storytelling
奇怪的家政:英国故事中不稳定的家庭地理
  • 批准号:
    2709419
  • 财政年份:
    2022
  • 资助金额:
    $ 55.44万
  • 项目类别:
    Studentship
Symbolism of the Heart as a Transplanted Organ: "You realize you have someone else's heart and it's kind of weird"
心脏作为移植器官的象征意义:“你意识到你有别人的心脏,这有点奇怪”
  • 批准号:
    304189
  • 财政年份:
    2014
  • 资助金额:
    $ 55.44万
  • 项目类别:
Foundation building of a "weird" study in a Japanese literature
日本文学“怪异”研究的基础构建
  • 批准号:
    23520245
  • 财政年份:
    2011
  • 资助金额:
    $ 55.44万
  • 项目类别:
    Grant-in-Aid for Scientific Research (C)
Are evolutionarily distinctive rockfish both weird and threaatened?
进化上独特的岩鱼是否既奇怪又受到威胁?
  • 批准号:
    367073-2008
  • 财政年份:
    2008
  • 资助金额:
    $ 55.44万
  • 项目类别:
    University Undergraduate Student Research Awards
Smashing two stars: weird giants?
粉碎两颗星星:奇怪的巨人?
  • 批准号:
    366483-2008
  • 财政年份:
    2008
  • 资助金额:
    $ 55.44万
  • 项目类别:
    University Undergraduate Student Research Awards
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了