在持续攻击之后恢复弹性和安全的芯片系统

Ahmad T. Sheikh, Ali Shoker, Paulo Esteves-Verissimo
{"title":"在持续攻击之后恢复弹性和安全的芯片系统","authors":"Ahmad T. Sheikh, Ali Shoker, Paulo Esteves-Verissimo","doi":"10.1145/3578357.3589456","DOIUrl":null,"url":null,"abstract":"To cope with the ever increasing threats of dynamic and adaptive persistent attacks, Fault and Intrusion Tolerance (FIT) is being studied at the hardware level to increase critical systems resilience. Based on state-machine replication, FIT is known to be effective if replicas are compromised and fail independently. This requires different ways of diversification at the software and hardware levels. In this paper, we introduce the first FIT hardware-based rejuvenation framework, we call Samsara, that allows for creating new FIT replicas with computing cores of diverse architectures. This is made possible by taking advantage of the reconfiguration features of MPSoC with FPGAs. A persistent attack that analyzes and exploits the vulnerability of a core will not be effective as rejuvenation using a different core architecture can be done periodically. Samsara allows for both replacing and adding/removing new cores to adapt to varying levels of threat severity. We introduce this concept and discuss the feasibility using a preliminary design we propose. A more rigorous study and empirical evaluation are left for future work.","PeriodicalId":158487,"journal":{"name":"Proceedings of the 16th European Workshop on System Security","volume":"56 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-05-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Resilient and Secure System on Chip with Rejuvenation in the Wake of Persistent Attacks\",\"authors\":\"Ahmad T. Sheikh, Ali Shoker, Paulo Esteves-Verissimo\",\"doi\":\"10.1145/3578357.3589456\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"To cope with the ever increasing threats of dynamic and adaptive persistent attacks, Fault and Intrusion Tolerance (FIT) is being studied at the hardware level to increase critical systems resilience. Based on state-machine replication, FIT is known to be effective if replicas are compromised and fail independently. This requires different ways of diversification at the software and hardware levels. In this paper, we introduce the first FIT hardware-based rejuvenation framework, we call Samsara, that allows for creating new FIT replicas with computing cores of diverse architectures. This is made possible by taking advantage of the reconfiguration features of MPSoC with FPGAs. A persistent attack that analyzes and exploits the vulnerability of a core will not be effective as rejuvenation using a different core architecture can be done periodically. Samsara allows for both replacing and adding/removing new cores to adapt to varying levels of threat severity. We introduce this concept and discuss the feasibility using a preliminary design we propose. A more rigorous study and empirical evaluation are left for future work.\",\"PeriodicalId\":158487,\"journal\":{\"name\":\"Proceedings of the 16th European Workshop on System Security\",\"volume\":\"56 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-05-08\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the 16th European Workshop on System Security\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3578357.3589456\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 16th European Workshop on System Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3578357.3589456","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

为了应对不断增长的动态和自适应持续攻击的威胁,人们正在硬件层面研究故障和入侵容忍(FIT),以提高关键系统的弹性。基于状态机复制,如果副本被破坏并独立失败,FIT是有效的。这需要在软件和硬件层面采取不同的多样化方式。在本文中,我们介绍了第一个基于硬件的FIT复兴框架,我们称之为Samsara,它允许使用不同架构的计算核心创建新的FIT副本。这可以通过利用MPSoC与fpga的重新配置功能来实现。分析和利用核心脆弱性的持续攻击将不会有效,因为使用不同的核心架构可以定期进行恢复。轮回允许替换和添加/删除新的核心,以适应不同级别的威胁严重程度。我们介绍了这一概念,并使用我们提出的初步设计讨论了可行性。更严格的研究和实证评价有待于今后的工作。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Resilient and Secure System on Chip with Rejuvenation in the Wake of Persistent Attacks
To cope with the ever increasing threats of dynamic and adaptive persistent attacks, Fault and Intrusion Tolerance (FIT) is being studied at the hardware level to increase critical systems resilience. Based on state-machine replication, FIT is known to be effective if replicas are compromised and fail independently. This requires different ways of diversification at the software and hardware levels. In this paper, we introduce the first FIT hardware-based rejuvenation framework, we call Samsara, that allows for creating new FIT replicas with computing cores of diverse architectures. This is made possible by taking advantage of the reconfiguration features of MPSoC with FPGAs. A persistent attack that analyzes and exploits the vulnerability of a core will not be effective as rejuvenation using a different core architecture can be done periodically. Samsara allows for both replacing and adding/removing new cores to adapt to varying levels of threat severity. We introduce this concept and discuss the feasibility using a preliminary design we propose. A more rigorous study and empirical evaluation are left for future work.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信