Skip to main content
QUICK REVIEW

[논문 리뷰] A Compiler Assisted Scheduler for Detecting and Mitigating Cache-Based Side Channel Attacks

Sharjeel Khan, Girish Mururu|arXiv (Cornell University)|2020. 03. 08.
Security and Verification in Computing참고 문헌 46인용 수 5
한 줄 요약

Biscuit는 멀티테넌시 서버 환경에서 캐시 기반 사이드채널 공격을 탐지하고 완화하기 위해 컴파일러가 지원하는 스케줄러로, 루프 진입부에 캐시 미스 비컨을 삽입하여 캐시 동작을 예측하고 모니터링한다. 정상 작동 시 6% 미만의 오버헤드로 Prime+Probe, Flush+Reload, Flush+Flush 공격을 100% F-스코어로 탐지하고, 공격 중에는 11% 미만의 오버헤드를 기록한다.

ABSTRACT

Side channel attacks steal secret keys by cleverly leveraging information leakages and can, therefore, break encryption. Thus, detection and mitigation of side channel attacks is a very important problem, but the solutions proposed in the literature have limitations in that they do not work in a real-world multi-tenancy setting on servers, have high false positives, or have high overheads. In this work, we demonstrate a compiler guided scheduler, Biscuit, that detects cache-based side channel attacks for processes scheduled on multi-tenancy server farms. A key element of this solution involves the use of a cache-miss model which is inserted by the compiler at the entrances of loop nests to predict the cache misses of the corresponding loop. Such inserted library calls, or beacons, convey the cache miss information to the scheduler at run time, which uses it to co-schedule processes such that their combined cache footprint does not exceed the maximum capacity of the last level cache. The scheduled processes are then monitored for actual vs predicted cache misses, and when an anomaly is detected, the scheduler performs a search to isolate the attacker. We show that Biscuit is able to detect and mitigate Prime+Probe, Flush+Reload, and Flush+Flush attacks on OpenSSL cryptography algorithms with an F-score of 1, and also to detect and mitigate degradation of service on a vision application suite with an F-score of 0.9375. Under a no-attack scenario, the scheme poses low overheads (up to a maximum of 6 percent). In the case of an attack, the scheme ends up with less than 11 percent overhead and is able to reduce the degradation of service in some cases by 40 percent. With these many desirable features such as an ability to deal with multi-tenancy, its ability to detect attacks early, its ability to mitigate those attacks, and low runtime overheads, Biscuit is a practical solution.

연구 동기 및 목표

  • 실세계의 멀티테넌시 서버 환경에서 캐시 기반 사이드채널 공격을 탐지하고 완화하기 위한 실용적이고 저비용인 솔루션의 부족을 해결한다.
  • 공유 인프라에서 확장성이 떨어지고 높은 가짜 경고 비율, 높은 런타임 오버헤드를 보이는 이전 솔루션의 한계를 극복한다.
  • 컴파일러 삽입 런타임 모니터링을 통해 키 추출 공격(예: Flush+Reload)과 서비스 제공도용(DoS) 공격을 조기에 탐지하고 완화할 수 있도록 한다.
  • 루프 수준의 정밀한 캐시 프로파일 예측을 통해 높은 탐지 정확도를 유지하면서도 낮은 성능 오버헤드를 확보한다.

제안 방법

  • 루프 네스트 진입부에 컴파일러가 생성한 '비컨'—캐시 미스 예측 함수—를 삽입하여 루프 범위에 기반해 런타임 동안의 캐시 미스를 추정한다.
  • 비컨 데이터를 활용해 프로세스를 함께 할당하여 병합된 캐시 프로파일이 최종 레벨 캐시(LLC) 용량을 초과하지 않도록 스케줄러를 가동한다.
  • 실행 중 실제 캐시 미스와 예측된 캐시 미스를 비교하여 잠재적인 사이드채널 공격을 나타내는 이질성을 탐지한다.
  • 이상 탐지 시 공격자 프로세스를 식별하고 완화하기 위해 고립 절차를 실행한다.
  • 루프 수준의 캐시 미스 모델링을 통해 정확한 예상 캐시 동작 예측을 통해 가짜 경고를 0으로 줄인다.
  • 기존의 OS 스케줄링 및 가상 메모리 고립 기능과 통합하여 하드웨어 변경 없이 실세계 멀티테넌시 서버 팜에서 작동한다.

실험 결과

연구 질문

  • RQ1컴파일러 지원 스케줄러는 실세계 멀티테넌시 서버 환경에서 캐시 기반 사이드채널 공격을 높은 정확도로 탐지할 수 있는가?
  • RQ2정밀한 루프 수준의 캐시 미스 예측은 사이드채널 탐지에서 가짜 경고를 어떻게 줄일 수 있는가?
  • RQ3정상 및 공격 상황에서 이러한 탐지 및 완화 시스템을 통합할 경우 런타임 오버헤드는 얼마나 되는가?
  • RQ4스케줄러는 성능을 유지하면서도 프로세스를 효과적으로 공유 스케줄링하여 캐시 기반 사이드채널 누출을 방지할 수 있는가?
  • RQ5시스템은 캐시 기반 공격으로 인한 서비스 품질 저하를 어느 정도 완화할 수 있는가?

주요 결과

  • Biscuit는 OpenSSL 암호화 워크로드에서 Prime+Probe, Flush+Reload, Flush+Flush 공격을 1.0의 F-스코어로 탐지한다.
  • 시각 애플리케이션 스위트에서는 Biscuit가 서비스 품질 저하 공격을 F-스코어 0.9375로 탐지한다.
  • 정상(공격 없음) 상황에서는 Biscuit가 최대 6%의 오버헤드만 유발하여 생산 환경 배포에 적합하다.
  • 공격 발생 시 오버헤드는 최대 11%로 증가하지만, 대부분의 워크로드에 대해 여전히 수용 가능한 수준이다.
  • 공격 상황에서 일부 벤치마크에서 Biscuit는 서비스 품질 저하를 최대 40%까지 감소시켜 효과적인 완화를 보여준다.
  • 컴파일러 삽입 비컨의 사용으로 루프 범위와 런타임 값에 기반한 정확한 캐시 미스 예측을 통해 가짜 경고를 0으로 줄일 수 있다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.