서브메뉴
검색
Secure Cache and Processor Architectures Against Side-Channel, Speculative Execution and Impostor Attacks
Secure Cache and Processor Architectures Against Side-Channel, Speculative Execution and Impostor Attacks
상세정보
- 자료유형
- 학위논문 서양
- 최종처리일시
- 20250211153027
- ISBN
- 9798346759157
- DDC
- 621.3
- 저자명
- Hu, Guangyuan.
- 서명/저자
- Secure Cache and Processor Architectures Against Side-Channel, Speculative Execution and Impostor Attacks
- 발행사항
- [Sl] : Princeton University, 2024
- 발행사항
- Ann Arbor : ProQuest Dissertations & Theses, 2024
- 형태사항
- 245 p
- 주기사항
- Source: Dissertations Abstracts International, Volume: 86-06, Section: B.
- 주기사항
- Advisor: Lee, Ruby B.
- 학위논문주기
- Thesis (Ph.D.)--Princeton University, 2024.
- 초록/해제
- 요약Modern computer systems are increasingly vulnerable to a growing number of attacks, with hardware caches being a critical performance optimization feature and a prime target for exploitation. Traditional cache timing attacks often aim to leak secrets like encryption keys, while recent speculative execution attacks can leak a broader range of sensitive information through cache timing channels.This dissertation focuses on designing efficient defenses to mitigate these threats. We begin by presenting an analytical framework that characterizes the security guarantees and performance overheads of defenses. Our analysis shows the need for a secure cache to defend against both side-channel and speculative execution attacks.To address these challenges, we propose the Speculative and Timing Attack Resilient (STAR) cache, designed to counter access-based cache attacks commonly exploited by attackers. We identify potential attacks that could compromise previous randomized caches and enhance the design to mitigate these vulnerabilities. To address speculative execution attacks, we introduce a novel invalidation mechanism that defeats attacks without adding extra work when speculation is correct.We further propose a novel cache architecture, the Random and Safe (RaS) cache, which changes the predictable fetch and placement policies of traditional caches. RaS prevents cache fills for demand-fetched, security-sensitive lines, instead filling the cache with "safe" lines that are randomly displaced to confuse attackers. RaS defeats the challenging same-domain attacks without changing the set-associative cache architecture. One variant, RaS-Spec, mitigates speculative execution attacks with minimal overhead. Another variant, RaS+, offers security-performance trade-offs to defend against both access-based and operation-based attacks.Beyond addressing microarchitectural threats, we also investigate methods for detecting anomalous behaviors, such as an unauthorized user (impostor) attempting to access a victim's smartphone. We propose the Smartphone Impostor Detector (SID), a processor architecture that supports a diverse set of attack detection algorithms, in scenarios both with and without other users' data for training. The SID processor provides flexible support for various machine learning, deep learning, and statistical algorithms at minimal cost, making it versatile enough to serve as a general-purpose anomaly detection module.
- 일반주제명
- Computer engineering
- 일반주제명
- Information technology
- 일반주제명
- Electrical engineering
- 키워드
- Secure cache
- 기타저자
- Princeton University Electrical and Computer Engineering
- 기본자료저록
- Dissertations Abstracts International. 86-06B.
- 전자적 위치 및 접속
- 로그인 후 원문을 볼 수 있습니다.
MARC
008250123s2024 us c eng d■001000017164650
■00520250211153027
■006m o d
■007cr#unu||||||||
■020 ▼a9798346759157
■035 ▼a(MiAaPQ)AAI31634348
■040 ▼aMiAaPQ▼cMiAaPQ
■0820 ▼a621.3
■1001 ▼aHu, Guangyuan.▼0(orcid)0009-0000-9554-258X
■24510▼aSecure Cache and Processor Architectures Against Side-Channel, Speculative Execution and Impostor Attacks
■260 ▼a[Sl]▼bPrinceton University▼c2024
■260 1▼aAnn Arbor▼bProQuest Dissertations & Theses▼c2024
■300 ▼a245 p
■500 ▼aSource: Dissertations Abstracts International, Volume: 86-06, Section: B.
■500 ▼aAdvisor: Lee, Ruby B.
■5021 ▼aThesis (Ph.D.)--Princeton University, 2024.
■520 ▼aModern computer systems are increasingly vulnerable to a growing number of attacks, with hardware caches being a critical performance optimization feature and a prime target for exploitation. Traditional cache timing attacks often aim to leak secrets like encryption keys, while recent speculative execution attacks can leak a broader range of sensitive information through cache timing channels.This dissertation focuses on designing efficient defenses to mitigate these threats. We begin by presenting an analytical framework that characterizes the security guarantees and performance overheads of defenses. Our analysis shows the need for a secure cache to defend against both side-channel and speculative execution attacks.To address these challenges, we propose the Speculative and Timing Attack Resilient (STAR) cache, designed to counter access-based cache attacks commonly exploited by attackers. We identify potential attacks that could compromise previous randomized caches and enhance the design to mitigate these vulnerabilities. To address speculative execution attacks, we introduce a novel invalidation mechanism that defeats attacks without adding extra work when speculation is correct.We further propose a novel cache architecture, the Random and Safe (RaS) cache, which changes the predictable fetch and placement policies of traditional caches. RaS prevents cache fills for demand-fetched, security-sensitive lines, instead filling the cache with "safe" lines that are randomly displaced to confuse attackers. RaS defeats the challenging same-domain attacks without changing the set-associative cache architecture. One variant, RaS-Spec, mitigates speculative execution attacks with minimal overhead. Another variant, RaS+, offers security-performance trade-offs to defend against both access-based and operation-based attacks.Beyond addressing microarchitectural threats, we also investigate methods for detecting anomalous behaviors, such as an unauthorized user (impostor) attempting to access a victim's smartphone. We propose the Smartphone Impostor Detector (SID), a processor architecture that supports a diverse set of attack detection algorithms, in scenarios both with and without other users' data for training. The SID processor provides flexible support for various machine learning, deep learning, and statistical algorithms at minimal cost, making it versatile enough to serve as a general-purpose anomaly detection module.
■590 ▼aSchool code: 0181.
■650 4▼aComputer engineering
■650 4▼aInformation technology
■650 4▼aElectrical engineering
■653 ▼aAnomaly detection
■653 ▼aComputer architecture
■653 ▼aHardware security
■653 ▼aSecure cache
■653 ▼aSide-channel attack
■653 ▼aSpeculative execution attack
■690 ▼a0464
■690 ▼a0489
■690 ▼a0544
■71020▼aPrinceton University▼bElectrical and Computer Engineering.
■7730 ▼tDissertations Abstracts International▼g86-06B.
■790 ▼a0181
■791 ▼aPh.D.
■792 ▼a2024
■793 ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17164650▼nKERIS▼z이 자료의 원문은 한국교육학술정보원에서 제공합니다.


