Skip to main content
QUICK REVIEW

[論文レビュー] A Compiler Assisted Scheduler for Detecting and Mitigating Cache-Based Side Channel Attacks

Sharjeel Khan, Girish Mururu|arXiv (Cornell University)|Mar 8, 2020
Security and Verification in Computing参考文献 46被引用数 5
ひとこと要約

Biscuit は、ループの入り口にキャッシュミスのブイエーションを挿入することで、キャッシュ動作を予測・監視し、マルチテナントサーバ環境におけるキャッシュベースの側面チャネル攻撃を検出・緩和するコンパイラ支援スケジューラである。通常動作時で6%未満、攻撃時で11%未満のオーバーヘッドで、Prime+Probe、Flush+Reload、Flush+Flush 攻撃の検出において100%のFスコアを達成する。

ABSTRACT

Side channel attacks steal secret keys by cleverly leveraging information leakages and can, therefore, break encryption. Thus, detection and mitigation of side channel attacks is a very important problem, but the solutions proposed in the literature have limitations in that they do not work in a real-world multi-tenancy setting on servers, have high false positives, or have high overheads. In this work, we demonstrate a compiler guided scheduler, Biscuit, that detects cache-based side channel attacks for processes scheduled on multi-tenancy server farms. A key element of this solution involves the use of a cache-miss model which is inserted by the compiler at the entrances of loop nests to predict the cache misses of the corresponding loop. Such inserted library calls, or beacons, convey the cache miss information to the scheduler at run time, which uses it to co-schedule processes such that their combined cache footprint does not exceed the maximum capacity of the last level cache. The scheduled processes are then monitored for actual vs predicted cache misses, and when an anomaly is detected, the scheduler performs a search to isolate the attacker. We show that Biscuit is able to detect and mitigate Prime+Probe, Flush+Reload, and Flush+Flush attacks on OpenSSL cryptography algorithms with an F-score of 1, and also to detect and mitigate degradation of service on a vision application suite with an F-score of 0.9375. Under a no-attack scenario, the scheme poses low overheads (up to a maximum of 6 percent). In the case of an attack, the scheme ends up with less than 11 percent overhead and is able to reduce the degradation of service in some cases by 40 percent. With these many desirable features such as an ability to deal with multi-tenancy, its ability to detect attacks early, its ability to mitigate those attacks, and low runtime overheads, Biscuit is a practical solution.

研究の動機と目的

  • 実世界のマルチテナントサーバ環境におけるキャッシュベースの側面チャネル攻撃の検出・緩和のための実用的で低オーバーヘッドなソリューションの不足に対処する。
  • 共有インフラでスケーラブルでない、高い誤検出率、高いランタイムオーバーヘッドといった、先行研究の制限を克服する。
  • コンパイラ挿入によるランタイム監視を活用し、鍵抽出攻撃(例:Flush+Reload)およびサービス劣化(DoS)攻撃の早期検出と緩和を可能にする。
  • ループレベルの粒度での正確なキャッシュフットプリント予測を通じて、高い検出精度を維持しつつ、低パフォーマンスオーバーヘッドを実現する。

提案手法

  • ループネストの入り口に、コンパイラが生成する「ビーコン」——キャッシュミス予測関数——を挿入し、ループの境界に基づいて実行時キャッシュミスを推定する。
  • ビーコンデータを活用して、合計キャッシュフットプリントが最後級キャッシュ(LLC)容量に収まるように、プロセスを共通割り当てするスケジューラを導入する。
  • 実行中に実際のキャッシュミスと予測されたキャッシュミスを比較し、潜在的な側面チャネル攻撃を示す異常を検出する。
  • 異常検出時に隔離手順をトリガーし、攻撃プロセスを特定・緩和する。
  • ループレベルのキャッシュミスモデルを活用することで、正確に予想されるキャッシュ動作を予測し、誤検出をゼロに抑える。
  • 既存のOSスケジューリングおよび仮想メモリ隔離機構と統合し、ハードウェア変更なしに実世界のマルチテナントサーバーファームで動作可能にする。

実験結果

リサーチクエスチョン

  • RQ1コンパイラ支援スケジューラは、実世界のマルチテナントサーバ環境で、キャッシュベースの側面チャネル攻撃を高い正確性で検出できるか?
  • RQ2正確なループレベルキャッシュミス予測は、サイドチャネル検出における誤検出をどのように低減できるか?
  • RQ3このような検出・緩和システムを統合した際の、通常時および攻撃時におけるランタイムオーバーヘッドはどの程度か?
  • RQ4スケジューラは、パフォーマンスを維持しつつ、プロセスを効果的に共スケジューリングし、キャッシュベースのサイドチャネル漏洩を防げるか?
  • RQ5このシステムは、キャッシュベースの攻撃によるサービス劣化をどの程度緩和できるか?

主な発見

  • Biscuit は、OpenSSL暗号化ワークロードにおいて、Prime+Probe、Flush+Reload、Flush+Flush 攻撃の検出において F スコア 1.0 を達成する。
  • ビジョンアプリケーションスイートでは、サービス劣化攻撃を F スコア 0.9375 で検出する。
  • 通常(攻撃なし)のシナリオでは、Biscuit は最大6%のオーバーヘッドを発生させ、生産環境への導入に適している。
  • 攻撃中はオーバーヘッドが最大11%に増加するが、これは大多数のワークロードにとって許容可能な範囲である。
  • 攻撃シナリオでは、一部のベンチマークでサービス劣化を最大40%まで低減でき、効果的な緩和が示された。
  • コンパイラ挿入ビーコンの使用により、ループ境界と実行時値に基づく正確なキャッシュミス予測が可能となり、誤検出をゼロに抑える。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。