当前位置: X-MOL 学术arXiv.cs.AR › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
Toward Taming the Overhead Monster for Data-Flow Integrity
arXiv - CS - Hardware Architecture Pub Date : 2021-02-19 , DOI: arxiv-2102.10031
Lang Feng, Jiayi Huang, Jeff Huang, Jiang Hu

Data-Flow Integrity (DFI) is a well-known approach to effectively detecting a wide range of software attacks. However, its real-world application has been quite limited so far because of the prohibitive performance overhead it incurs. Moreover, the overhead is enormously difficult to overcome without substantially lowering the DFI criterion. In this work, an analysis is performed to understand the main factors contributing to the overhead. Accordingly, a hardware-assisted parallel approach is proposed to tackle the overhead challenge. Simulations on SPEC CPU 2006 benchmark show that the proposed approach can completely verify the DFI defined in the original seminal work while reducing performance overhead by 4x on average.

中文翻译:

努力驯服开销怪兽以实现数据流完整性

数据流完整性(DFI)是一种有效检测各种软件攻击的公知方法。但是,到目前为止,由于它产生的性能开销过大,其实际应用受到很大限制。而且,在不显着降低DFI标准的情况下,开销很难克服。在这项工作中,进行分析以了解造成开销的主要因素。因此,提出了一种硬件辅助的并行方法来解决开销挑战。在SPEC CPU 2006基准测试上的仿真表明,该方法可以完全验证原始开创性工作中定义的DFI,同时平均将性能开销降低4倍。
更新日期:2021-02-22
down
wechat
bug