HDFI: Hardware-Assisted Data-Flow Isolation

2016 IEEE Symposium on Security and Privacy (SP)(2016)

引用 153|浏览159
暂无评分
摘要
Memory corruption vulnerabilities are the root cause of many modern attacks. Existing defense mechanisms are inadequate; in general, the software-based approaches are not efficient and the hardware-based approaches are not flexible. In this paper, we present hardware-assisted data-flow isolation, or, HDFI, a new fine-grained data isolation mechanism that is broadly applicable and very efficient. HDFI enforces isolation at the machine word granularity by virtually extending each memory unit with an additional tag that is defined by dataflow. This capability allows HDFI to enforce a variety of security models such as the Biba Integrity Model and the Bell -- LaPadula Model. We implemented HDFI by extending the RISC-V instruction set architecture (ISA) and instantiating it on the Xilinx Zynq ZC706 evaluation board. We ran several benchmarks including the SPEC CINT 2000 benchmark suite. Evaluation results show that the performance overhead caused by our modification to the hardware is low (<; 2%). We also developed or ported several security mechanisms to leverage HDFI, including stack protection, standard library enhancement, virtual function table protection, code pointer protection, kernel data protection, and information leak prevention. Our results show that HDFI is easy to use, imposes low performance overhead, and allows us to create more elegant and more secure solutions.
更多
查看译文
关键词
HDFI,hardware-assisted data-flow isolation,memory corruption vulnerability,software-based approach,fine-grained data isolation mechanism,security model,Biba integrity model,Bell --LaPadula model,RISC-V instruction set architecture,Xilinx Zynq ZC706 evaluation board,stack protection,standard library enhancement,virtual function table protection,code pointer protection,kernel data protection,information leak prevention
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要