IOSEC - Protection and Memory Safety for Input/Output Security
IOSEC - Protection and Memory Safety for Input/Output Security
批准号:
EP/R012458/1
负责人:
Robert Watson
金额:
$65.23万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2018
资助国家:
英国
项目状态:
已结题
起止时间:
2018 至 --
中文摘要
点击翻译按钮获取中文摘要
英文摘要
We wish to re-architect current computer input/output (I/O) systems with security as a first-class design constraint. Existing I/O has evolved organically over the decades and now faces a 'perfect storm' of security vulnerabilities, which we aim to address.Computers today are full of processors: advertised, hidden and even unintentional. Processors, in the form of embedded microcontrollers, are hidden in 'devices' that we name as 'wireless card' or 'system management controller', but fundamentally they form a heterogenous distributed system. The software these processors run is often poorly scrutinised and may be actively malicious. As this field becomes more visible, vulnerabilities are being discovered with increasing frequency.Worse still, the trend is for 'pluggable' devices via interfaces such as USB Type-C and Thunderbolt 3: users are being trained to pick up processors, thinking they are innocuous because theyare shaped like chargers or dongles. For instance, many buildings, aircraft, trains and buses now provide 'USB charging', but, without protection, the Type-C user may be exposing themselves to unexpected threats. Such threats are of substantial and increasing concern to businesses, government and consumers. By redesigning I/O with security at the core, we aim to considerably improve on today's weaknesses. We will investigate the weaknesses of current I/O and propose safer alternatives through three threads of research:1. We will begin by performing a survey of the state-of-the-art of access-control protections in current hardware and software designs, to understand the limits of current pluggable-device security. We will focus in particular on current utilisation of Input/Output Memory Management Units (IOMMUs), which are the primary current defence that prevents devices from having unlimited Direct Memory Access (DMA) - the 'key to the kingdom' of system security that otherwise permits total compromise of firmware, OS, and applications from malicious devices. We will characterise current security-performance tradeoffs to establish a performance baseline. We will systemise new vulnerability classes and develop a corpus of vector-specific attack techniques which future defences must prevent or mitigate.Our existing preliminary results investigating IOMMU use in modern operating systems, and a growing attack literature, suggest substantial security and performance shortcomings. We therefore propose two strands of research to develop and evaluate technical approaches to defend against I/O-based attackers:2. Many I/O devices (e.g., USB and network cards) communicate with the host operating system through messages sent and received via DMA. We will develop new techniques to restructure CPU-to-I/O interconnects to provide a message-based abstraction for untrustworthy devices, rather than depending on DMA, as is current (and highly vulnerable) best practice.3. To address devices for which a memory-oriented semantic is intrinsic (e.g., GPUs and Remote-DMA enabled network cards), we will explore new distributed-memory protection techniques that avoid the granularity and performance limitations of IOMMU-oriented approaches. This will enable greater control of device access to host memory while improving security-performance tradeoffs. For instance we might delegate specific memory access rights to devices, with policy and unforgeability enforced by the interconnect bridges.All research will be performed via hardware-software co-design methodology and FPGA prototyping, with evaluation relative to performance, complexity, compatibility, and security metrics for both hardware and software. We will pursue these goals in close collaboration with ARM Ltd, who provide key insights into industry requirements and a transition path into commercial technologies.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/sp40000.2020.00098
发表时间:
2020-05
期刊:
2020 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
作者:
[N. Filardo;B. F. Gutstein;Jonathan Woodruff;S. Ainsworth;Lucian Paul-Trifu;Brooks Davis;Hongyan Xia;E. Napierala;Alexander Richardson;John Baldwin;D. Chisnall;Jessica Clarke;Khilan Gudka;Alexandre Joannou;A. T. Markettos;Alfredo Mazzinghi;Robert M. Norton;M. Roe;Peter Sewell;Stacey D. Son;Timothy M. Jones;S. Moore;P. Neumann;R. Watson]
通讯作者:
N. Filardo;B. F. Gutstein;Jonathan Woodruff;S. Ainsworth;Lucian Paul-Trifu;Brooks Davis;Hongyan Xia;E. Napierala;Alexander Richardson;John Baldwin;D. Chisnall;Jessica Clarke;Khilan Gudka;Alexandre Joannou;A. T. Markettos;Alfredo Mazzinghi;Robert M. Norton;M. Roe;Peter Sewell;Stacey D. Son;Timothy M. Jones;S. Moore;P. Neumann;R. Watson
Through computer architecture, darkly
通过计算机体系结构,黑暗
DOI:
10.1145/3325284
发表时间:
2019
期刊:
Communications of the ACM
影响因子:
22.7
作者:
[Markettos A]
通讯作者:
Markettos A
Thunderclap: Exploring Vulnerabilities in Operating System IOMMU Protection via DMA from Untrustworthy Peripherals
Thunderclap:通过来自不可信外设的 DMA 探索操作系统 IOMMU 保护中的漏洞
DOI:
10.14722/ndss.2019.23194
发表时间:
2019
期刊:
影响因子:
--
作者:
[Markettos A]
通讯作者:
Markettos A
CHERI Concentrate: Practical Compressed Capabilities
CHERI Concentrate:实用的压缩功能
DOI:
10.1109/tc.2019.2914037
发表时间:
2019
期刊:
IEEE Transactions on Computers
影响因子:
3.7
作者:
[Woodruff J]
通讯作者:
Woodruff J
CHERIvoke
奇瑞沃克
DOI:
10.1145/3352460.3358288
发表时间:
2019
期刊:
影响因子:
--
作者:
[Xia H]
通讯作者:
Xia H
共 6 条
CHERI for Hypervisors and Operating Systems (CHaOS)
-
批准号:EP/V000292/1
-
项目类别:Research Grant
-
资助金额:$111.92万
-
财政年份:2020
-
负责人:Robert Watson
-
依托单位:
QFC: Quantum Fibre Clock
-
批准号:EP/S000232/1
-
项目类别:Research Grant
-
资助金额:$23.99万
-
财政年份:2018
-
负责人:Robert Watson
-
依托单位:
FEMTO: FEmtosecond Measurement Technology Options
-
批准号:EP/M508251/1
-
项目类别:Research Grant
-
资助金额:$22.8万
-
财政年份:2015
-
负责人:Robert Watson
-
依托单位:
SENTINEL: GNSS SErvices Needing Trust In Navigation, Electronics, Location & timing
-
批准号:TS/I00257X/1
-
项目类别:Research Grant
-
资助金额:$27.49万
-
财政年份:2011
-
负责人:Robert Watson
-
依托单位:
The utilization of digital television and radio signals for atmospheric science
-
批准号:NE/I000933/1
-
项目类别:Research Grant
-
资助金额:$13.64万
-
财政年份:2010
-
负责人:Robert Watson
-
依托单位:
A study of the climatic dependency of rainfall rate dynamics for use in the design of fade mitigation techniques
-
批准号:EP/D057930/1
-
项目类别:Research Grant
-
资助金额:$3.88万
-
财政年份:2006
-
负责人:Robert Watson
-
依托单位:
海外基金