DocumentCode :
3516646
Title :
Decoupling Dynamic Information Flow Tracking with a dedicated coprocessor
Author :
Kannan, Hari ; Dalton, Michael ; Kozyrakis, Christos
Author_Institution :
Comput. Syst. Lab., Stanford Univ., Stanford, CA, USA
fYear :
2009
fDate :
June 29 2009-July 2 2009
Firstpage :
105
Lastpage :
114
Abstract :
Dynamic information flow tracking (DIFT) is a promising security technique. With hardware support, DIFT prevents a wide range of attacks on vulnerable software with minimal performance impact. DIFT architectures, however, require significant changes in the processor pipeline that increase design and verification complexity and may affect clock frequency. These complications deter hardware vendors from supporting DIFT. This paper makes hardware support for DIFT cost effective by decoupling DIFT functionality onto a simple, separate coprocessor. Decoupling is possible because DIFT operations and regular computation need only synchronize on system calls. The coprocessor is a small hardware engine that performs logical operations and caches 4-bit tags. It introduces no changes to the design or layout of the main processor´s logic, pipeline, or caches, and can be combined with various processors. Using a full-system hardware prototype and realistic Linux workloads, we show that the DIFT coprocessor provides the same security guarantees as current DIFT architectures with low runtime overheads.
Keywords :
Linux; coprocessors; data flow computing; pipeline processing; special purpose computers; DIFT architecture; clock frequency; coprocessor; decoupling dynamic information flow tracking; dedicated coprocessor; design complexity; hardware support; hardware vendor; logical operation; processors cache; processors logic; processors pipeline; realistic Linux workload; software security technique; storage capacity 4 bit; verification complexity; Clocks; Computer architecture; Coprocessors; Cost function; Engines; Frequency synchronization; Hardware; Information security; Pipelines; Software performance; Coprocessors; Dynamic information flow tracking; Processor architecture; Semantic Vulnerabilities; Software security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems & Networks, 2009. DSN '09. IEEE/IFIP International Conference on
Conference_Location :
Lisbon
Print_ISBN :
978-1-4244-4422-9
Electronic_ISBN :
978-1-4244-4421-2
Type :
conf
DOI :
10.1109/DSN.2009.5270347
Filename :
5270347
Link To Document :
بازگشت