CellIFT: Leveraging Cells for Scalable and Precise Dynamic Information Flow Tracking in RTL
Flavien Solt, Ben Gras, Kaveh Razavi
摘要
Dynamic Information Flow Tracking (dynamic IFT) is a wellknown technique with many security applications such as analyzing the behavior of a system given an input and detecting security violations. While there are many widely used open dynamic IFT solutions that scale to large software, the same level of support is unfortunately lacking for hardware. This gap is becoming more pronounced with the increasing complexity of open-source hardware and the plethora of recent hardware attacks. We introduce CELLIFT, a new design point in the space of dynamic IFT for hardware. CELLIFT leverages the logical macrocell abstraction (e.g., an adder) to achieve scalability, precision and completeness when instrumenting a given Register Transfer Level (RTL) hardware design. Cell-level dynamic IFT does not suffer from the scalability problems that are inherent to lower levels of abstraction such as gates, yet it achieves completeness given the limited number of cell types. We show the versatility of CELLIFT by instrumenting five distinct RISC-V designs, one of which is a complete SoC. The only existing complete solution already fails to instrument two of these designs. Our extensive evaluation using microbenchmarks and standard RISC-V benchmarks on the instrumented designs shows that CELLIFT is 21× to 61× faster than the state of the art in terms of simulation runtime without losing precision. We further show-case concrete applications of CELLIFT in four scenarios by detecting: 1) sources of microarchitectural information leakage, 2) microarchitectural bugs such as Meltdown, 3) speculative vulnerabilities such as Spectre-BCB, and 4) SoC-wide architectural design flaws. We release CELLIFT as open source to enable RTLlevel security research for the wider community.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- Cascade: CPU Fuzzing via Intricate Program GenerationFlavien Solt, Katharina Ceesay-Seitz, Kaveh RazaviUSENIX Security 2024 · 被引用 46 次
- RTL Verification for Secure Speculation Using Contract Shadow LogicQinhan Tan, Yuheng Yang, Thomas Bourgeat, Sharad Malik 等ASPLOS 2025 · 被引用 12 次
- RTL2MμPATH: Multi-μPATH Synthesis with Applications to Hardware Security VerificationYao Hsiao, Nikos Nikoleris, Artem Khyzha, Dominic P. Mulligan 等MICRO 2024 · 被引用 12 次
- RemembERR: Leveraging Microprocessor Errata for Design Testing and ValidationFlavien Solt, Patrick Jattke, Kaveh RazaviMICRO 2022 · 被引用 12 次
- TEESec: Pre-Silicon Vulnerability Discovery for Trusted Execution EnvironmentsMoein Ghaniyoun, Kristin Barber, Yuan Xiao, Yinqian Zhang 等ISCA 2023 · 被引用 6 次
它引用的顶会 Paper22
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp 等USENIX Security 2019 · 被引用 442 次
相关 Paper
- Lost and Found in Speculation: Hybrid Speculative Vulnerability DetectionMohamadreza Rostami, Shaza Zeitouni, Rahul Kande, Chen Chen 等DAC 2024 · 被引用 6 次
- Dynamic Information Flow Tracking for Embedded Binaries using SystemC-based Virtual PrototypesPascal Pieper, Vladimir Herdt, Daniel Große, Rolf DrechslerDAC 2020 · 被引用 22 次
- A Security RISC: Microarchitectural Attacks on Hardware RISC-V CPUsLukas Gerlach, Daniel Weber, Ruiyi Zhang, Michael SchwarzS&P 2023
- SpecCFI: Mitigating Spectre Attacks using CFI Informed SpeculationEsmaeil Mohammadian Koruyeh, Shirin Haji Amin Shirazi, Khaled N. Khasawneh, Chengyu Song 等S&P 2020 · 被引用 74 次
- Speculation at Fault: Modeling and Testing Microarchitectural Leakage of CPU ExceptionsJana Hofmann, Emanuele Vannacci, Cédric Fournet, Boris Köpf 等USENIX Security 2023
