共 31 条
Arbitrary Precision and Complexity Tradeoffs for Gate-Level Information Flow Tracking
被引:0
|作者:
Becker, Andrew
[1
]
Hu, Wei
[2
]
Tai, Yu
[3
]
Brisk, Philip
[4
]
Kastner, Ryan
[2
]
Ienne, Paolo
[1
]
机构:
[1] Ecole Polytech Fed Lausanne, CH-1011 Lausanne, Switzerland
[2] Univ Calif San Diego, La Jolla, CA 92093 USA
[3] Northwestern Polytech Univ, Xian 710072, Shaanxi, Peoples R China
[4] Univ Calif Riverside, Riverside, CA 92521 USA
关键词:
D O I:
10.1145/3061639.3062203
中图分类号:
TM [电工技术];
TN [电子技术、通信技术];
学科分类号:
0808 ;
0809 ;
摘要:
Hardware has become an increasingly attractive target for attackers, yet we still largely lack tools that enable us to analyze large designs for security flaws. Information flow tracking (IFT) models provide an approach to verifying a hardware design's adherence to security properties related to isolation and reachability. However, existing precise IFT models are usually too complex to actually use. Queries may fail to finish even for small designs when verifying relatively simple properties. It is possible to create less complex models, but these come at the cost of a severe loss of precision-they frequently indicate a property fails when in fact it passes, which means verification requires extensive additional manual investigation. We present a new method to bridge the chasm between precision and complexity in a finer-grained, controlled, and disciplined manner. Our method allows using the most appropriate precision/complexity tradeoff for the design size and available computing resources, meaning it is now possible to create models that are not too complex to be usable, but which offer more precision (fewer false positives) than was previously possible.
引用
收藏
页数:6
相关论文