首页> 外文会议>IEEE European Test Symposium >LiD-CAT: A Lightweight Detector for Cache ATtacks
【24h】

LiD-CAT: A Lightweight Detector for Cache ATtacks

机译:LiD-CAT:用于高速缓存攻击的轻型检测器

获取原文

摘要

Cache attacks are one of the most wide-spread and dangerous threats to embedded computing systems' security. A promising approach to detect such attacks at runtime is to monitor the System-on-Chip (SoC) behavior. However, designing a secure SoC capable of detecting such attacks is very challenging: the monitors should be lightweight in order to avoid excessive power/energy and area costs and the attack behavior should be clearly known upfront. In this work, we present LiD-CAT, a lightweight and flexible hardware detector that is aware of leakage patterns that can be used by attackers to perform cache based attacks. LiD-CAT is a cache wrapper that implements a set of leakage properties derived from cache attacks and cache models using templates. These templates identify suspicious behavior that may lead to cache attacks. LiD-CAT is evaluated using two different cache architectures, one with a secure cache and one without. On each of them, SPEC2000 benchmarks are run together with malicious applications that execute cache attacks (i.e., Evict+Time, Prime+Probe, Flush+Reload and Flush+Flush). Results show that our lightweight detector successfully detects 99.99% of the attacks with less than 1% false-positives, has no timing penalties, and increases the area of a SoC with only 1.6%.
机译:缓存攻击是对嵌入式计算系统安全性最广泛,最危险的威胁之一。在运行时检测此类攻击的一种有前途的方法是监视片上系统(SoC)行为。但是,设计一种能够检测到此类攻击的安全SoC非常具有挑战性:监控器应轻巧,以避免过多的功率/能量和面积成本,并且应预先明确知道攻击行为。在这项工作中,我们介绍了LiD-CAT,这是一种轻巧灵活的硬件检测器,它了解攻击者可以用来执行基于缓存的攻击的泄漏模式。 LiD-CAT是一个缓存包装器,它使用模板来实现从缓存攻击和缓存模型派生的一组泄漏属性。这些模板识别可导致缓存攻击的可疑行为。 LiD-CAT使用两种不同的缓存架构进行评估,一种具有安全缓存,另一种不具有。 SPEC2000基准测试在每一个上均与执行缓存攻击的恶意应用程序一起运行(即,Evict + Time,Prime + Probe,Flush + Reload和Flush + Flush)。结果表明,我们的轻量级检测器成功检测出99.99%的攻击,且假阳性率不到1%,没有计时损失,而SoC的面积仅增加了1.6%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号