HAFIX: Hardware-Assisted Flow Integrity Extension

Seminar of  Institute of Information Systems and Applications 

 

Speaker:   Prof. Yier Jin 

                    (University of Central Florida))

Topic:       HAFIX: Hardware-Assisted Flow Integrity Extension

Date :        13:2015:00  Monday 14 Dec. 2015

Place :      R615 Delta Building

Host :      Prof. Tsung-Yi Ho

 

 

Abstract :

Code-reuse attacks have become the state-of-the-art technique to exploit memory-related vulnerabilities in modern software. These attacks require no code injection. That is, they hijack the intended control-flow of applications and redirect it to unintended but valid code sequences. Hence, these attacks circumvent non-executable memory protection against code injection attacks, which is currently deployed on many computing platforms including Intel, ARM, and SPARC. The most general solution against ROP is control-flow integrity (CFI) as it restricts program execution to a pre-defined control-flow graph (CFG). However, the original CFI proposal suffers from practical deficiencies, most notably performance overhead. Hence, recent CFI approaches aim at a tradeoff between security and practicality. However, these so-called coarse-grained CFI policies can be undermined as shown recently. Until now, the majority of research on CFI has focused on software-based solutions. This presentation will introduce a hardware-based CFI approach that has several advantages over software-based counterparts: First, it is significantly more efficient, as we demonstrate. Second, compiler support is simplified by reducing complex CFI checking code to single CFI instructions. Third, dedicated CFI hardware instructions and separate CFI memory provide strong protection of critical CFI control-flow data. 

Bio :

Yier Jin is currently an assistant professor in the EECS Department at the University of Central Florida. He received his PhD degree in Electrical Engineering in 2012 from Yale University after he got the B.S. and M.S. degrees in Electrical Engineering from Zhejiang University, China, in 2005 and 2007, respectively. His research focuses on the areas of trusted embedded systems, trusted hardware intellectual property (IP) cores and hardware-software co-protection on computer systems. He proposed various approaches in the area of hardware security, including the hardware Trojan detection methodology relying on local side-channel information, the post-deployment hardware trust assessment framework, and the proof-carrying hardware IP protection scheme. He is also interested in the security analysis on Internet of Things (IoT) and wearable devices with particular emphasis on information integrity and privacy protection in the IoT era. He is the best paper award recipient of the 52nd Design Automation Conference in 2015. He serves and has served on the Organizing Committees and Technical Program Committees of many Conferences and Workshops such as DAC, ICCAD, ASPDAC, HOST, ISVLSI, ICCD, etc.  

All faculty and students are welcome to join the lecture