CAREER: Weird Machines: a New Foundation for Advancing Microarchitectural Security
CAREER: Weird Machines: a New Foundation for Advancing Microarchitectural Security
批准号:
2145635
负责人:
Dmitry Evtyushkin
金额:
$55.44万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-07-01 至 2027-06-30
中文摘要
中央处理器(CPU)是典型计算系统的关键部件。为了提高cpu的性能,现代cpu的微体系结构包含多个子系统,这些子系统具有复杂的内部状态和功能。在提高性能的同时,这些子系统经常引发意想不到的可观察到的副作用,这些副作用已知会导致攻击,导致敏感数据泄露。CPU组件不断增长的复杂性和跨组件交互的复杂性使得检测这种影响变得具有挑战性。这个CAREER项目利用了怪异机器的概念,这是一个理论框架,可以通过计算理论来分析安全漏洞。根据这一概念,漏洞在原始计算实体中创建了一个新的计算模型,其属性不是其设计所期望的。以前,奇怪的机器主要用于研究软件系统。这个CAREER项目利用奇怪机器的概念来系统地识别MA的副作用,并探索它们如何被潜在的攻击者使用。研究者发现,MA组件的相互作用在CPU微体系结构中创建了一个新的可编程计算模型,而现有的分析方法是不可见的。同时,它还可以用于隐藏恶意活动或触发意外的系统行为。该项目的新奇之处在于:1)使用奇怪机器的概念来研究MA安全性;2)探索MA副作用的计算能力;3)研究新的计算模型的用例。该项目更广泛的意义和重要性在于:1)提高对现代计算机系统攻击面的理解;2)建立一种识别和记录MA副作用的新方法,用于研究和教育。这个CAREER项目主要有三个目标。首先,已知的MA副作用被记录为奇怪的机器原语,然后自动搜索新的副作用。其次,研究了奇异机的计算能力和实用性,包括奇异机的可编程性和提高奇异机可靠性的方法。此外,该项目还探索了构建能够进行任意计算的通用MA怪机的可行性。第三,将建立的MA怪机框架应用于研究已知的MA攻击类型,如侧信道,从而发现新的攻击变体。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The Central Processing Unit (CPU) is a key element of a typical computing system. To improve performance, microarchitecture (MA) of modern CPUs include multiple sub-systems with complex internal state and functionality. While improving performance, these sub-systems often trigger unexpected observable side-effects which are known to enable attacks resulting in sensitive data leakage. The ever-growing complexity of CPU components and the complex nature of the cross-component interaction make it challenging to detect such effects. This CAREER project utilizes the concept of weird machines, a theoretical framework that enables analyzing security vulnerabilities via the theory of computation. According to this concept, vulnerabilities create a new computational model within the original computational entity with properties not intended by its design. Previously, weird machines were mostly used to study software systems. This CAREER project utilizes the concept of weird machines to systematically identify MA side effects and explore how they can be used by a potential attacker. The investigator has discovered that the interaction of MA components creates a new programmable computational model within the CPU microarchitecture that is invisible to existing methods of analysis. At the same time, it can be used to hide malicious activities or to trigger unexpected systems behaviors. The project’s novelties are 1) using the concept of weird machines to study MA security, 2) exploring computational capabilities of MA side effects, 3) investigating use cases for the new model of computation. The project's broader significance and importance are 1) improving the understanding of the attack surface in modern computer systems, 2) establishing a new approach for identifying and documenting MA side effects to be used for research and education.This CAREER project is centered on three main objectives. First, known MA side-effects are documented as weird machine primitives, followed by an automated search for new side-effects. Second, the computational capabilities and practicality of MA weird machines are investigated including programmability of such machines and methods to improve their reliability. In addition, the project explores the feasibility of constructing a universal MA weird machine capable of performing arbitrary computations. Third, the established MA weird machines framework is applied to study known types of MA attacks, such as side channels, enabling discovery of new attack variants.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CRII: SaTC: Secure Branch Predictors for High Performance Processors
-
批准号:1850365
-
项目类别:Standard Grant
-
资助金额:$17.5万
-
财政年份:2019
-
负责人:Dmitry Evtyushkin
-
依托单位:
海外基金