中文版 | English
题名

SPECBOX: A Label-Based Transparent Speculation Scheme Against Transient Execution Attacks

作者
发表日期
2022
DOI
发表期刊
ISSN
1545-5971
EISSN
1941-0018
卷号PP期号:99页码:1-1
摘要
Speculative execution techniques have been a cornerstone of modern processors to improve instruction-level parallelism. However, recent studies showed that this kind of techniques could be exploited by attackers to leak secret data via transient execution attacks, such as Spectre. Many defenses are proposed to address this problem, but they all face various challenges: (1) Filtering data flow in the instruction pipeline could comprehensively address this problem, but it could cause pipeline stalls and incur high performance overhead; (2) Making side effect of speculative execution imperceptible to attackers often needs additional storage components and and complicated data movement operations. In this paper, we propose a label-based transparent speculation scheme called SpecBox. It dynamically partitions the cache system to isolate speculative data and non-speculative data, which can prevent transient execution from being observed by subsequent execution. Moreover, it uses thread ownership semaphores to prevent speculative data from being accessed across cores. In addition, SpecBox also enhances the auxiliary components in the cache system against transient execution attacks, such as hardware prefetcher. Our security analysis shows that Specbox is secure and the performance evaluation shows that SpecBox only incurs a very small performance overhead on SPEC CPU 2006 and PARSEC-3.0 benchmarks.
关键词
相关链接[Scopus记录]
收录类别
EI ; SCI
语种
英语
学校署名
其他
资助项目
National Natural Science Foundation of China (NSFC)["61902374","U1736208"] ; NSF[CNS-1514444]
WOS研究方向
Computer Science
WOS类目
Computer Science, Hardware & Architecture ; Computer Science, Information Systems ; Computer Science, Software Engineering
WOS记录号
WOS:000923069400056
出版者
EI入藏号
20220511570116
EI主题词
Access control ; Benchmarking ; Digital storage ; Network security ; Pipeline processing systems ; Pipelines
EI分类号
Pipe, Piping and Pipelines:619.1 ; Data Storage, Equipment and Techniques:722.1 ; Digital Computers and Systems:722.4 ; Computer Software, Data Handling and Applications:723
Scopus记录号
2-s2.0-85123724093
来源库
Scopus
全文链接https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=9689943
引用统计
被引频次[WOS]:1
成果类型期刊论文
条目标识符http://sustech.caswiz.com/handle/2SGJ60CL/327926
专题工学院_计算机科学与工程系
作者单位
1.Key Laboratory of Computer System and Architecture, Institute of Computing Technology Chinese Academy of Sciences, 53035 Beijing, Beijing, China, (e-mail: tangbowen@ict.ac.cn)
2.State Key Laboratory of Computer Architecture, Institute of Computing Technology Chinese Academy of Sciences, 53035 Beijing, Beijing, China, (e-mail: wucg@ict.ac.cn)
3.State Key Laboratory of Computer Architecture, Institute of Computing Technology Chinese Academy of Sciences, 53035 Beijing, Beijing, China, (e-mail: wangzhe12@ict.ac.cn)
4.State Key Laboratory of Computer Architecture, Institute of Computing Technology Chinese Academy of Sciences, 53035 Beijing, Beijing, China, (e-mail: bwtang91@gmail.com)
5.Department of Computer Science and Engineering, University of Minnesota Twin Cities, 5635 Minneapolis, Minnesota, United States, (e-mail: yew@umn.edu)
6.Head of Security Research, NIO, Mountain View, California, United States, (e-mail: strongerwill@gmail.com)
7.Department of Computer Science and Engineering, Southern University of Science and Technology, 255310 Shenzhen, Guangdong, China, (e-mail: yinqianz@acm.org)
8.Computer Science Department, University of California Los Angeles, 8783 Los Angeles, California, United States, (e-mail: wangchenxi@cs.ucla.edu)
9.CS, University of California Los Angeles, 8783 Los Angeles, California, United States, 90095 (e-mail: harryxu@cs.ucla.edu)
推荐引用方式
GB/T 7714
Tang,Bowen,Wu,Chenggang,Wang,Zhe,et al. SPECBOX: A Label-Based Transparent Speculation Scheme Against Transient Execution Attacks[J]. IEEE Transactions on Dependable and Secure Computing,2022,PP(99):1-1.
APA
Tang,Bowen.,Wu,Chenggang.,Wang,Zhe.,Jia,Lichen.,Yew,Pen Chung.,...&Xu,Guoqing.(2022).SPECBOX: A Label-Based Transparent Speculation Scheme Against Transient Execution Attacks.IEEE Transactions on Dependable and Secure Computing,PP(99),1-1.
MLA
Tang,Bowen,et al."SPECBOX: A Label-Based Transparent Speculation Scheme Against Transient Execution Attacks".IEEE Transactions on Dependable and Secure Computing PP.99(2022):1-1.
条目包含的文件
条目无相关文件。
个性服务
原文链接
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
导出为Excel格式
导出为Csv格式
Altmetrics Score
谷歌学术
谷歌学术中相似的文章
[Tang,Bowen]的文章
[Wu,Chenggang]的文章
[Wang,Zhe]的文章
百度学术
百度学术中相似的文章
[Tang,Bowen]的文章
[Wu,Chenggang]的文章
[Wang,Zhe]的文章
必应学术
必应学术中相似的文章
[Tang,Bowen]的文章
[Wu,Chenggang]的文章
[Wang,Zhe]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
[发表评论/异议/意见]
暂无评论

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。