...
首页> 外文期刊>IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems >ABCFI: Fast and Lightweight Fine-Grained Hardware-Assisted Control-Flow Integrity
【24h】

ABCFI: Fast and Lightweight Fine-Grained Hardware-Assisted Control-Flow Integrity

机译:ABCFI:快速轻巧的细粒度硬件辅助控制流程完整性

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Code-reuse attack is a severe threat to computer systems as it can circumvent many existing security defenses and perform arbitrary behavior. Control-flow integrity (CFI) is a security technique that restricts control-flow transfers to prevent the attack. Although CFI has been implemented via various methods, including hardware-assisted extensions, the current designs of hardware-assisted fine-grained CFI fail to meet practical needs. The main hurdles include: 1) the lack of cost-effective design and 2) insufficient security as they cannot enforce a complete control-flow graph (CFG) with only one label for each target. This article presents a novel hardware-assisted fine-grained CFI design that reformulates labels as the lower bits of addresses (called address-based CFI). Thus, it costs negligible runtime overhead (<= 0.55%) and hardware overhead (only ten LUTs and no flip flop based on coarse-grained extension). Among all the current hardware-assisted fine-grained CFI designs, ABCFI has the lowest hardware overhead and runtime performance overhead. With our novel design, the commercial coarse-grained CFI extensions can be advanced to fine-grained CFI extensions through few efforts.
机译:代码重用攻击是对计算机系统的严重威胁,因为它可以规避许多现有的安全防御并执行任意行为。控制流程完整性(CFI)是一种安全技术,限制控制流量转移以防止攻击。虽然CFI已通过各种方法实施,但包括硬件辅助扩展,但硬件辅助细粒度CFI的当前设计无法满足实用需求。主要障碍包括:1)缺乏成本效益的设计和2)安全性不足,因为它们不能为每个目标强制执行完整的控制流程图(CFG)。本文介绍了一种新型硬件辅助细粒度CFI设计,可重新重新格式化标签作为地址的较低位(称为地址为基础的CFI)。因此,运行时耗尽(<= 0.55%)和硬件开销(仅基于粗粒粒度扩展的10 LUT和触发器)成本可忽略不计。在所有当前的硬件辅助精细粒度CFI设计中,ABCFI具有最低的硬件开销和运行时性能开销。凭借我们的新设计,通过少量努力,商业粗粒度CFI延伸可以进入细粒度的CFI扩展。

著录项

  • 来源
  • 作者单位

    Chinese Acad Sci Inst Informat Engn Beijing 100093 Peoples R China|Univ Chinese Acad Sci Sch Cyber Secur Beijing 100049 Peoples R China;

    Chinese Acad Sci Inst Informat Engn Beijing 100093 Peoples R China|Univ Chinese Acad Sci Sch Cyber Secur Beijing 100049 Peoples R China;

    Chinese Acad Sci Inst Informat Engn Beijing 100093 Peoples R China|Univ Chinese Acad Sci Sch Cyber Secur Beijing 100049 Peoples R China;

    Chinese Acad Sci Inst Informat Engn Beijing 100093 Peoples R China|Univ Chinese Acad Sci Sch Cyber Secur Beijing 100049 Peoples R China;

    Chinese Acad Sci Inst Informat Engn Beijing 100093 Peoples R China|Univ Chinese Acad Sci Sch Cyber Secur Beijing 100049 Peoples R China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Control-flow integrity (CFI); intrusion detection;

    机译:控制流程完整性(CFI);入侵检测;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号