中文版 | English
题名

RAFT: Hardware-assisted Dynamic Information Flow Tracking for Runtime Protection on RISC-V

作者
通讯作者Zhang,Fengwei
DOI
发表日期
2023-10-16
会议名称
RAID 2023
会议录名称
页码
595-608
会议日期
2023.10.16
会议地点
Hong Kong
出版地
1601 Broadway, 10th Floor, NEW YORK, NY, UNITED STATES
出版者
摘要

Dynamic Information Flow Tracking (DIFT) is a fundamental computer security technique that tracks the data flow of interest at runtime, overcoming the limitations of discovering data dependencies statically at compilation time. However, software-based DIFT tools often suffer from unbearably high runtime overhead due to dynamic binary instrumentation or virtual machine, limiting the usefulness of DIFT. Even though hardware-assisted DIFT frameworks cut down the performance overhead effectively, it is still unacceptable for applications under rigorous time constraints. This paper presents Raft, a flexible hardware-assisted DIFT framework that provides runtime protection for embedded applications without delay to the programs. Our framework is designed as a coprocessor for a RISC-V Rocket Core, introducing minimallyinvasive changes to the main processor. In Raft, we apply a novel storage mechanism with hybrid byte/variable granularity to reduce the size of tag storage and provide fine-grained protection. We deploy Raft on the Rocket emulator and FPGA development board to evaluate its effectiveness and efficiency. The experiment results show that, compared to previous approaches, Raft cuts down the performance overhead from more than 20% to less than 0.1% on NBench and CoreMark microbenchmarks. The performance overhead of Raft on SPEC CINT 2006 benchmarks is negligible (0.13%). We also utilize a customized program to demonstrate its functionality and conduct a detailed evaluation with a real-world embedded medical application and known CVEs.

关键词
学校署名
第一 ; 通讯
语种
英语
相关链接[Scopus记录]
收录类别
资助项目
National Natural Science Foundation of China["62002151","62102175"] ; Shenzhen Science and Technology Program["SGDX20201103095408029","ZDSYS20210623092007023"]
WOS研究方向
Computer Science
WOS类目
Computer Science, Information Systems ; Computer Science, Theory & Methods
WOS记录号
WOS:001147724400040
EI入藏号
20234515025505
EI主题词
Application programs ; Digital storage ; Rockets
EI分类号
Rockets and Missiles:654.1 ; Data Storage, Equipment and Techniques:722.1 ; Computer Software, Data Handling and Applications:723
Scopus记录号
2-s2.0-85175711968
来源库
Scopus
引用统计
成果类型会议论文
条目标识符http://sustech.caswiz.com/handle/2SGJ60CL/602176
专题工学院_斯发基斯可信自主研究院
工学院_计算机科学与工程系
作者单位
1.Research Institute of Trustworthy Autonomous Systems,Southern University of Science and Technology,China
2.Department of Computer Science and Engineering,Southern University of Science and Technology,China
3.Hunan University,China Southern University of Science and Technology,China
4.Huawei Technologies Co.,Ltd,China
5.Shenzhen Key Laboratory of Safety and Security for Next Generation of Industrial Internet,Southern University of Science and Technology,China
第一作者单位斯发基斯可信自主系统研究院;  计算机科学与工程系
通讯作者单位计算机科学与工程系;  南方科技大学
第一作者的第一单位斯发基斯可信自主系统研究院
推荐引用方式
GB/T 7714
Wang,Yu,Wu,Jinting,Zheng,Haodong,et al. RAFT: Hardware-assisted Dynamic Information Flow Tracking for Runtime Protection on RISC-V[C]. 1601 Broadway, 10th Floor, NEW YORK, NY, UNITED STATES:ASSOC COMPUTING MACHINERY,2023:595-608.
条目包含的文件
文件名称/大小 文献类型 版本类型 开放类型 使用许可 操作
RAFT 2023.pdf(730KB)----开放获取--浏览
个性服务
原文链接
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
导出为Excel格式
导出为Csv格式
Altmetrics Score
谷歌学术
谷歌学术中相似的文章
[Wang,Yu]的文章
[Wu,Jinting]的文章
[Zheng,Haodong]的文章
百度学术
百度学术中相似的文章
[Wang,Yu]的文章
[Wu,Jinting]的文章
[Zheng,Haodong]的文章
必应学术
必应学术中相似的文章
[Wang,Yu]的文章
[Wu,Jinting]的文章
[Zheng,Haodong]的文章
相关权益政策
暂无数据
收藏/分享
文件名: RAFT 2023.pdf
格式: Adobe PDF
文件名: RAFT 2023.pdf
格式: Adobe PDF
所有评论 (0)
[发表评论/异议/意见]
暂无评论

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。