首页> 外文会议>IEEE International Symposium on High Performance Computer Architecture >Record-Replay Architecture as a General Security Framework
【24h】

Record-Replay Architecture as a General Security Framework

机译:记录重放架构作为通用安全框架

获取原文

摘要

Hardware security features need to strike a careful balance between design intrusiveness and completeness of methods. In addition, they need to be flexible, as security threats continuously evolve. To help address these requirements, this paper proposes a novel framework where Record and Deterministic Replay (RnR) is used to complement hardware security features. We call the framework RnR-Safe. RnR-Safe reduces the cost of security hardware by allowing it to be less precise at detecting attacks, potentially reporting false positives. This is because it relies on on-the-fly replay that transparently verifies whether the alarm is a real attack or a false positive. RnR-Safe uses two replayers: an always-on, fast Checkpoint replayer that periodically creates checkpoints, and a detailed-analysis Alarm replayer that is triggered when there is a threat alarm. As an example application, we use RnR-Safe to thwart Return Oriented Programming (ROP) attacks, including on the Linux kernel. Our design augments the Return Address Stack (RAS) with relatively inexpensive hardware. We evaluate RnR-Safe using a variety of workloads on virtual machines running Linux. We find that RnR-Safe is very effective. Thanks to the judicious RAS hardware extensions and hypervisor changes, the checkpointing replayer has an execution speed comparable to the recorded execution. Also, the alarm replayer needs to handle very few false positives.
机译:硬件安全功能需要在设计侵入性和方法完整性之间取得谨慎的平衡。此外,随着安全威胁的不断发展,它们必须具有灵活性。为了帮助满足这些要求,本文提出了一个新颖的框架,其中记录和确定性重放(RnR)用于补充硬件安全功能。我们称该框架为RnR-Safe。 RnR-Safe通过降低检测攻击的准确性(可能报告误报),从而降低了安全硬件的成本。这是因为它依赖于动态重放,可以透明地验证警报是真正的攻击还是误报。 RnR-Safe使用两个重播器:一个始终在线的快速Checkpoint重播器,它定期创建检查点;以及一个详细分析警报重播器,该警报重播器在出现威胁警报时触发。作为示例应用程序,我们使用RnR-Safe来阻止返回定向编程(ROP)攻击,包括在Linux内核上。我们的设计使用相对便宜的硬件扩展了返回地址堆栈(RAS)。我们在运行Linux的虚拟机上使用各种工作负载评估RnR-Safe。我们发现RnR-Safe非常有效。由于明智的RAS硬件扩展和虚拟机管理程序更改,检查点重播器的执行速度与记录的执行速度相当。同样,警报重播器需要处理很少的误报。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号