The Experts below are selected from a list of 867 Experts worldwide ranked by ideXlab platform
David Mazieres - One of the best experts on this subject based on the ideXlab platform.
-
eliminating cache based timing attacks with Instruction based scheduling
European Symposium on Research in Computer Security, 2013Co-Authors: Deian Stefan, Pablo Buiras, Edward Yang, Amit Levy, David Terei, Alejandro Russo, David MazieresAbstract:Information flow control allows untrusted code to access sensitive and trustworthy information without leaking this information. However, the presence of covert channels subverts this security mechanism, allowing processes to communicate information in violation of IFC policies. In this paper, we show that concurrent deterministic IFC systems that use time-based scheduling are vulnerable to a cache-based internal timing channel. We demonstrate this vulnerability with a concrete attack on Hails, one particular IFC web framework. To eliminate this internal timing channel, we implement Instruction-based scheduling, a new kind of scheduler that is indifferent to timing perturbations from underlying hardware components, such as the cache, TLB, and CPU buses. We show this scheduler is secure against cache-based internal timing attacks for applications using a single CPU. To show the feasibility of Instruction-based scheduling, we have implemented a version of Hails that uses the CPU Retired-Instruction counters available on commodity Intel and AMD hardware. We show that Instruction-based scheduling does not impose significant performance penalties. Additionally, we formally prove that our modifications to Hails’ underlying IFC system preserve non-interference in the presence of caches.
-
Eliminating cache-based timing attacks with Instruction-based scheduling: Extended version. http: //www.cse.chalmers.se/~buiras/esorics2013_extended.pdf
2013Co-Authors: Deian Stefan, Pablo Buiras, Amit Levy, David Terei, Edward Z. Yang, Ro Russo, David MazieresAbstract:Abstract. Information flow control allows untrusted code to access sensitive and trustworthy information without leaking this information. However, the presence of covert channels subverts this security mechanism, allowing processes to com-municate information in violation of IFC policies. In this paper, we show that concurrent deterministic IFC systems that use time-based scheduling are vulner-able to a cache-based internal timing channel. We demonstrate this vulnerability with a concrete attack on Hails, one particular IFC web framework. To eliminate this internal timing channel, we implement Instruction-based scheduling, a new kind of scheduler that is indifferent to timing perturbations from underlying hard-ware components, such as the cache, TLB, and CPU buses. We show this sched-uler is secure against cache-based internal timing attacks for applications using a single CPU. To show the feasibility of Instruction-based scheduling, we have im-plemented a version of Hails that uses the CPU Retired-Instruction counters avail-able on commodity Intel and AMD hardware. We show that Instruction-based scheduling does not impose significant performance penalties. Additionally, we formally prove that our modifications to Hails ’ underlying IFC system preserve non-interference in the presence of caches.
Deian Stefan - One of the best experts on this subject based on the ideXlab platform.
-
eliminating cache based timing attacks with Instruction based scheduling
European Symposium on Research in Computer Security, 2013Co-Authors: Deian Stefan, Pablo Buiras, Edward Yang, Amit Levy, David Terei, Alejandro Russo, David MazieresAbstract:Information flow control allows untrusted code to access sensitive and trustworthy information without leaking this information. However, the presence of covert channels subverts this security mechanism, allowing processes to communicate information in violation of IFC policies. In this paper, we show that concurrent deterministic IFC systems that use time-based scheduling are vulnerable to a cache-based internal timing channel. We demonstrate this vulnerability with a concrete attack on Hails, one particular IFC web framework. To eliminate this internal timing channel, we implement Instruction-based scheduling, a new kind of scheduler that is indifferent to timing perturbations from underlying hardware components, such as the cache, TLB, and CPU buses. We show this scheduler is secure against cache-based internal timing attacks for applications using a single CPU. To show the feasibility of Instruction-based scheduling, we have implemented a version of Hails that uses the CPU Retired-Instruction counters available on commodity Intel and AMD hardware. We show that Instruction-based scheduling does not impose significant performance penalties. Additionally, we formally prove that our modifications to Hails’ underlying IFC system preserve non-interference in the presence of caches.
-
Eliminating cache-based timing attacks with Instruction-based scheduling: Extended version. http: //www.cse.chalmers.se/~buiras/esorics2013_extended.pdf
2013Co-Authors: Deian Stefan, Pablo Buiras, Amit Levy, David Terei, Edward Z. Yang, Ro Russo, David MazieresAbstract:Abstract. Information flow control allows untrusted code to access sensitive and trustworthy information without leaking this information. However, the presence of covert channels subverts this security mechanism, allowing processes to com-municate information in violation of IFC policies. In this paper, we show that concurrent deterministic IFC systems that use time-based scheduling are vulner-able to a cache-based internal timing channel. We demonstrate this vulnerability with a concrete attack on Hails, one particular IFC web framework. To eliminate this internal timing channel, we implement Instruction-based scheduling, a new kind of scheduler that is indifferent to timing perturbations from underlying hard-ware components, such as the cache, TLB, and CPU buses. We show this sched-uler is secure against cache-based internal timing attacks for applications using a single CPU. To show the feasibility of Instruction-based scheduling, we have im-plemented a version of Hails that uses the CPU Retired-Instruction counters avail-able on commodity Intel and AMD hardware. We show that Instruction-based scheduling does not impose significant performance penalties. Additionally, we formally prove that our modifications to Hails ’ underlying IFC system preserve non-interference in the presence of caches.
Pablo Buiras - One of the best experts on this subject based on the ideXlab platform.
-
eliminating cache based timing attacks with Instruction based scheduling
European Symposium on Research in Computer Security, 2013Co-Authors: Deian Stefan, Pablo Buiras, Edward Yang, Amit Levy, David Terei, Alejandro Russo, David MazieresAbstract:Information flow control allows untrusted code to access sensitive and trustworthy information without leaking this information. However, the presence of covert channels subverts this security mechanism, allowing processes to communicate information in violation of IFC policies. In this paper, we show that concurrent deterministic IFC systems that use time-based scheduling are vulnerable to a cache-based internal timing channel. We demonstrate this vulnerability with a concrete attack on Hails, one particular IFC web framework. To eliminate this internal timing channel, we implement Instruction-based scheduling, a new kind of scheduler that is indifferent to timing perturbations from underlying hardware components, such as the cache, TLB, and CPU buses. We show this scheduler is secure against cache-based internal timing attacks for applications using a single CPU. To show the feasibility of Instruction-based scheduling, we have implemented a version of Hails that uses the CPU Retired-Instruction counters available on commodity Intel and AMD hardware. We show that Instruction-based scheduling does not impose significant performance penalties. Additionally, we formally prove that our modifications to Hails’ underlying IFC system preserve non-interference in the presence of caches.
-
Eliminating cache-based timing attacks with Instruction-based scheduling: Extended version. http: //www.cse.chalmers.se/~buiras/esorics2013_extended.pdf
2013Co-Authors: Deian Stefan, Pablo Buiras, Amit Levy, David Terei, Edward Z. Yang, Ro Russo, David MazieresAbstract:Abstract. Information flow control allows untrusted code to access sensitive and trustworthy information without leaking this information. However, the presence of covert channels subverts this security mechanism, allowing processes to com-municate information in violation of IFC policies. In this paper, we show that concurrent deterministic IFC systems that use time-based scheduling are vulner-able to a cache-based internal timing channel. We demonstrate this vulnerability with a concrete attack on Hails, one particular IFC web framework. To eliminate this internal timing channel, we implement Instruction-based scheduling, a new kind of scheduler that is indifferent to timing perturbations from underlying hard-ware components, such as the cache, TLB, and CPU buses. We show this sched-uler is secure against cache-based internal timing attacks for applications using a single CPU. To show the feasibility of Instruction-based scheduling, we have im-plemented a version of Hails that uses the CPU Retired-Instruction counters avail-able on commodity Intel and AMD hardware. We show that Instruction-based scheduling does not impose significant performance penalties. Additionally, we formally prove that our modifications to Hails ’ underlying IFC system preserve non-interference in the presence of caches.
Amit Levy - One of the best experts on this subject based on the ideXlab platform.
-
eliminating cache based timing attacks with Instruction based scheduling
European Symposium on Research in Computer Security, 2013Co-Authors: Deian Stefan, Pablo Buiras, Edward Yang, Amit Levy, David Terei, Alejandro Russo, David MazieresAbstract:Information flow control allows untrusted code to access sensitive and trustworthy information without leaking this information. However, the presence of covert channels subverts this security mechanism, allowing processes to communicate information in violation of IFC policies. In this paper, we show that concurrent deterministic IFC systems that use time-based scheduling are vulnerable to a cache-based internal timing channel. We demonstrate this vulnerability with a concrete attack on Hails, one particular IFC web framework. To eliminate this internal timing channel, we implement Instruction-based scheduling, a new kind of scheduler that is indifferent to timing perturbations from underlying hardware components, such as the cache, TLB, and CPU buses. We show this scheduler is secure against cache-based internal timing attacks for applications using a single CPU. To show the feasibility of Instruction-based scheduling, we have implemented a version of Hails that uses the CPU Retired-Instruction counters available on commodity Intel and AMD hardware. We show that Instruction-based scheduling does not impose significant performance penalties. Additionally, we formally prove that our modifications to Hails’ underlying IFC system preserve non-interference in the presence of caches.
-
Eliminating cache-based timing attacks with Instruction-based scheduling: Extended version. http: //www.cse.chalmers.se/~buiras/esorics2013_extended.pdf
2013Co-Authors: Deian Stefan, Pablo Buiras, Amit Levy, David Terei, Edward Z. Yang, Ro Russo, David MazieresAbstract:Abstract. Information flow control allows untrusted code to access sensitive and trustworthy information without leaking this information. However, the presence of covert channels subverts this security mechanism, allowing processes to com-municate information in violation of IFC policies. In this paper, we show that concurrent deterministic IFC systems that use time-based scheduling are vulner-able to a cache-based internal timing channel. We demonstrate this vulnerability with a concrete attack on Hails, one particular IFC web framework. To eliminate this internal timing channel, we implement Instruction-based scheduling, a new kind of scheduler that is indifferent to timing perturbations from underlying hard-ware components, such as the cache, TLB, and CPU buses. We show this sched-uler is secure against cache-based internal timing attacks for applications using a single CPU. To show the feasibility of Instruction-based scheduling, we have im-plemented a version of Hails that uses the CPU Retired-Instruction counters avail-able on commodity Intel and AMD hardware. We show that Instruction-based scheduling does not impose significant performance penalties. Additionally, we formally prove that our modifications to Hails ’ underlying IFC system preserve non-interference in the presence of caches.
David Terei - One of the best experts on this subject based on the ideXlab platform.
-
eliminating cache based timing attacks with Instruction based scheduling
European Symposium on Research in Computer Security, 2013Co-Authors: Deian Stefan, Pablo Buiras, Edward Yang, Amit Levy, David Terei, Alejandro Russo, David MazieresAbstract:Information flow control allows untrusted code to access sensitive and trustworthy information without leaking this information. However, the presence of covert channels subverts this security mechanism, allowing processes to communicate information in violation of IFC policies. In this paper, we show that concurrent deterministic IFC systems that use time-based scheduling are vulnerable to a cache-based internal timing channel. We demonstrate this vulnerability with a concrete attack on Hails, one particular IFC web framework. To eliminate this internal timing channel, we implement Instruction-based scheduling, a new kind of scheduler that is indifferent to timing perturbations from underlying hardware components, such as the cache, TLB, and CPU buses. We show this scheduler is secure against cache-based internal timing attacks for applications using a single CPU. To show the feasibility of Instruction-based scheduling, we have implemented a version of Hails that uses the CPU Retired-Instruction counters available on commodity Intel and AMD hardware. We show that Instruction-based scheduling does not impose significant performance penalties. Additionally, we formally prove that our modifications to Hails’ underlying IFC system preserve non-interference in the presence of caches.
-
Eliminating cache-based timing attacks with Instruction-based scheduling: Extended version. http: //www.cse.chalmers.se/~buiras/esorics2013_extended.pdf
2013Co-Authors: Deian Stefan, Pablo Buiras, Amit Levy, David Terei, Edward Z. Yang, Ro Russo, David MazieresAbstract:Abstract. Information flow control allows untrusted code to access sensitive and trustworthy information without leaking this information. However, the presence of covert channels subverts this security mechanism, allowing processes to com-municate information in violation of IFC policies. In this paper, we show that concurrent deterministic IFC systems that use time-based scheduling are vulner-able to a cache-based internal timing channel. We demonstrate this vulnerability with a concrete attack on Hails, one particular IFC web framework. To eliminate this internal timing channel, we implement Instruction-based scheduling, a new kind of scheduler that is indifferent to timing perturbations from underlying hard-ware components, such as the cache, TLB, and CPU buses. We show this sched-uler is secure against cache-based internal timing attacks for applications using a single CPU. To show the feasibility of Instruction-based scheduling, we have im-plemented a version of Hails that uses the CPU Retired-Instruction counters avail-able on commodity Intel and AMD hardware. We show that Instruction-based scheduling does not impose significant performance penalties. Additionally, we formally prove that our modifications to Hails ’ underlying IFC system preserve non-interference in the presence of caches.