System and method for uncovering covert timing channels

US10185824B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10185824-B2
Application numberUS-201515313785-A
CountryUS
Kind codeB2
Filing dateMay 26, 2015
Priority dateMay 23, 2014
Publication dateJan 22, 2019
Grant dateJan 22, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system detects a covert timing channel on a combinational structure or a memory structure. The system identifies the events behind conflicts, and constructs an event train based on those events. For combinational structures, the system detects recurrent burst patterns in the event train. The system determines that a covert timing channel exists on the combinational structure if a recurrent burst pattern is detected. For memory structures, the system detects oscillatory patterns in the event train. The system determines that a covert timing channel exists on the memory structure if an oscillatory pattern is detected.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for detecting a covert timing channel in a hardware device having a plurality of a memory hardware structures, the method comprising: selecting, by an instruction set architecture having a special instruction, a memory hardware structure from the plurality of memory hardware structures; identifying by a conflict miss tracker hardware, cache conflict miss events at the selected memory hardware structure, said identifying comprising: tracking by the conflict miss tracker hardware, generations comprising a set of cache blocks that are recently accessed for the selected memory hardware structure, wherein a set of generation bits are within the metadata for each cache block; recording by a bloom filter, replaced cache blocks in the cache block generation for the selected memory hardware structure; and identifying at the conflict miss tracker hardware, an event comprising a conflict miss when the bloom filter records a replaced cache block that was replaced by a more recently accessed cache block in the same generation or a younger generation; constructing an event train based on those cache conflict miss events identified by the conflict miss tracker hardware; detecting in the event trains on the conflict miss tracker hardware, oscillating patterns in the event train; determining by the conflict miss tracker hardware, that a covert timing channel exists on the selected memory hardware structure at a microarchitecture-level if an oscillatory pattern is detected. 2. A system for detecting a covert timing channel on hardware device having a plurality of memory hardware structures, said system comprising: an instruction set architecture having a special instruction to select a memory hardware structure from the plurality of memory hardware structures; a conflict miss tracker hardware configured to identify cache conflict miss events for the selected memory hardware structure, construct an event train based on those events, detect oscillatory patterns in the event train, and determine that a covert timing channel exists on the selected memory hardware structure at a microarchitecture-level if an oscillatory pattern is detected, wherein said conflict miss tracker hardware comprises: a set of generation bits within the metadata for each cache block configured to track generations, each generation comprising a set of cache blocks that are recently accessed for the selected memory hardware structure; a bloom filter configured to record replaced cache blocks in said cache block generation for the selected memory hardware structure; and wherein said conflict miss tracker hardware identifies an event comprising a conflict miss when said bloom filter records a replaced cache block that was replaced by a more recently accessed cache block in the same generation or a younger generation. 3. The system of claim 2 , wherein the selected memory hardware structure comprises one of an instruction cache, data cache, and a level-2 cache. 4. The system of claim 2 , wherein said special instruction selects a subset of memory hardware structures from the plurality of memory hardware structures, the subset of memory hardware structures comprising a plurality of selected memory hardware structures; and wherein said conflict miss tracker hardware identifies events, constructs an event train, detects oscillatory patterns, and determines that a covert timing channel exists, for each one of the subset of selected memory hardware structures. 5. A system for detecting a covert timing channel in a hardware device having a plurality of combinational hardware structures and a plurality of memory hardware structures, said system comprising: an instruction set architecture having a special instruction to select one or more combinational hardware structures from the plurality of combinational hardware structures, and one or more memory hardware structures from the plurality of memory hardware structures; a monitor hardware configured to monitor the selected one or more combinational hardware structures at a microarchitecture-level, accumulate microarchitecture-level events at the selected one or more combinational hardware structures, construct an event train based on those accumulated microarchitecture-level events, detect recurrent burst patterns in the event train, and determine that a covert timing channel exists on the selected one or more combinational hardware structures at a microarchitecture-level if a recurrent burst pattern is detected; and a conflict miss tracker hardware configured to identify cache conflict miss events for the selected one or more memory hardware structures, construct an event train based on those identified events, detect oscillatory patterns in the event train, and determine that a covert timing channel exists on the selected one or more memory hardware structures at a microarchitecture-level if an oscillatory pattern is detected, wherein said conflict miss tracker hardware comprises: a set of generation bits within the metadata for each cache block configured to track generations, each generation comprising a set of cache blocks that are recently accessed for the selected memory hardware structure; a bloom filter configured to record replaced cache blocks in said cache block generation for the selected memory hardware structure; wherein said conflict miss tracker hardware identifies an event comprising a conflict miss when said bloom filter records a replaced cache block that was replaced by a more recently accessed cache block in the same generation or a younger generation. 6. The system of claim 5 , wherein event information pertaining to the plurality of combinational hardware structures is accumulated in one or more registers. 7. The system of claim 5 , wherein event information pertaining to the plurality of memory hardware structures is accumulated in one or more vector registers. 8. The system of claim 5 , wherein the plurality of combinational hardware structures each comprise one of an integer arithmetic unit, floating point unit, a memory bus controller, and an interconnect. 9. The system of claim 5 , wherein said monitor hardware detects recurrent burst patterns by determining an interval for a given event train to calculate event density, construct an event density histogram and detect burst patterns, identity significant burst patterns, and determine recurrence of significant bursts. 10. The system of claim 9 , wherein the interval is a multiple of a cycle for the selected combinational hardware structure. 11. The system of claim 10 , wherein the interval is 100,000 CPU cycles. 12. The system of claim 9 , wherein the interval is an inverse of average event rate and an empirical constant based on a maximum and minimum achievable covert timing channel bandwidth rate for the selected combinational hardware structure. 13. The system of claim 9 , wherein the event density histogram includes an estimate a probability distribution of event density based on a number of events for each interval. 14. The system of claim 9 , wherein significant burst patterns are based on a likelihood ratio for a distribution in the event train. 15. The system of claim 9 , wherein if a significant burst pattern is detected, then further determining recurrent patterns of burst. 16. The system of claim 5 , said monitor hardware is further configured to receive events from the selected combinational hardware structure and construct the event train, whereby the event train comprises an occurrence of the received events for the selected combinational hardware structure.

Assignees

Inventors

Classifications

  • for timing attacks · CPC title

  • G06F21/556Primary

    involving covert channels, i.e. data leakage between processes (inhibiting the analysis of circuitry or operation with measures against power attack G06F21/755) · CPC title

  • by executing in a restricted environment, e.g. sandbox or secure virtual machine · CPC title

  • interconnection devices, e.g. bus-connected or in-line devices · CPC title

  • Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10185824B2 cover?
A system detects a covert timing channel on a combinational structure or a memory structure. The system identifies the events behind conflicts, and constructs an event train based on those events. For combinational structures, the system detects recurrent burst patterns in the event train. The system determines that a covert timing channel exists on the combinational structure if a recurrent bu…
Who is the assignee on this patent?
Univ George Washington
What technology area does this patent fall under?
Primary CPC classification G06F21/556. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jan 22 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 6 related publications on this page (citations in our corpus or others sharing the same primary CPC).