首页> 外文会议>International Symposium on Advanced Parallel Processing Technologies >CBA-Detector: An Accurate Detector Against Cache-Based Attacks Using HPCs and Pintools
【24h】

CBA-Detector: An Accurate Detector Against Cache-Based Attacks Using HPCs and Pintools

机译:CBA检测器:使用HPC和Pintools对基于缓存的攻击进行准确的检测器

获取原文

摘要

Cloud computing is convenient to provide adequate resources for tenants, but it suffers from information disclosure risks because hardware resources are shared among multiple tenants. For example, secret information in the shared cache can be inferred by other malicious processes, which is called cache-based attacks. To defeat against such attacks, many detection methods have been proposed. However, most of the existing detection mechanisms completely rely on the hardware performance counters (HPCs) and induce high false positives in detecting attacks. This paper proposes an accurate detector named CBA-Detector to detect cache-based side-channel attacks in real time. CBA-Detector is composed of an offline analysis phase and an online detection phase. The former analyzes the hardware events generated by sample programs. Then it extracts features from these events to train machine learning models. Based on the models, the latter monitors active processes in real time to discover suspicious processes. These suspicious processes will be checked again at the instruction level by customized Pintools, which effectively eliminates false positives. As shown in our experiments, CBA-Detector can accurately identify attacks in real time and introduces 4.4% overhead on PARSEC and about 10% overhead on web server.
机译:云计算方便为租户提供足够的资源,但它受到信息披露风险,因为硬件资源在多个租户之间共享。例如,可以通过其他恶意进程推断共享缓存中的秘密信息,这些过程称为基于缓存的攻击。为了防止这种攻击,已经提出了许多检测方法。然而,大多数现有的检测机制完全依赖于硬件性能计数器(HPC)并在检测攻击时引起高误报。本文提出了一种名为CBA检测器的精确检测器,以实时检测基于缓存的侧通道攻击。 CBA检测器由离线分析阶段和在线检测阶段组成。前者分析了示例程序生成的硬件事件。然后它从这些事件中提取特征以训练机器学习模型。基于模型,后者实时监控活动流程以发现可疑的过程。这些可疑过程将通过定制的铲斗再次检查指令级别,从而有效地消除了误报。如我们实验所示,CBA检测器可以实时准确地识别攻击,并在PARSEC上引入4.4%的开销和Web服务器上的大约10%开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号