Security-first architecture: deploying physically isolated active security processors for safeguarding the future of computing

计算机科学 计算机安全 安全性测试 建筑 软件安全保证 计算机安全模型 企业信息安全体系结构 保安服务 云安全计算 分布式计算 嵌入式系统 安全信息和事件管理 云计算 信息安全 操作系统 艺术 视觉艺术
作者
Dan Meng,Rui Hou,Gang Shi,Bibo Tu,Aimin Yu,Ziyuan Zhu,Xiaoqi Jia,Peng Liu
出处
期刊:Cybersecurity [Springer Nature]
卷期号:1 (1) 被引量:12
标识
DOI:10.1186/s42400-018-0001-z
摘要

It is fundamentally challenging to build a secure system atop the current computer architecture. The complexity in software, hardware and ASIC manufacture has reached beyond the capability of existing verification methodologies. Without whole-system verification, current systems have no proven security. It is observed that current systems are exposed to a variety of attacks due to the existence of a large number of exploitable security vulnerabilities. Some vulnerabilities are difficult to remove without significant performance impact because performance and security can be conflicting with each other. Even worse, attacks are constantly evolving, and sophisticated attacks are now capable of systematically exploiting multiple vulnerabilities while remain hidden from detection. Eagering to achieve security hardening of current computer architecture, existing defenses are mostly ad hoc and passive in nature. They are normally developed in responding to specific attacks spontaneously after specific vulnerabilities were discovered. As a result, they are not yet systematic in protecting systems from existing attacks and likely defenseless in front of zero-day attacks. To confront the aforementioned challenges, this paper proposes Security-first Architecture, a concept which enforces systematic and active defenses using Active Security Processors. In systems built based on this concept, traditional processors (i.e., Computation Processors) are monitored and protected by Active Security Processors. The two types of processors execute on their own physically-isolated resources, including memory, disks, network and I/O devices. The Active Security Processors are provided with dedicated channels to access all the resources of the Computation Processors but not vice versa. This allows the Active Security Processors to actively detect and tackle malicious activities in the Computation Processors with minimum performance degradation while protecting themselves from the attacks launched from the Computation Processors thanks to the resource isolation.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
小马甲应助ybwei2008_163采纳,获得10
1秒前
陈尹蓝完成签到 ,获得积分10
3秒前
spy完成签到 ,获得积分10
5秒前
strama完成签到,获得积分10
5秒前
21秒前
Aaernan完成签到 ,获得积分10
25秒前
SDNUDRUG发布了新的文献求助10
27秒前
沐雨篱边完成签到 ,获得积分10
31秒前
科研通AI5应助山山而川采纳,获得10
33秒前
keyana25完成签到,获得积分10
45秒前
1523完成签到 ,获得积分10
46秒前
46秒前
山山而川发布了新的文献求助10
52秒前
beplayer1完成签到,获得积分10
53秒前
所所应助SDNUDRUG采纳,获得10
54秒前
Sun1c7完成签到,获得积分10
57秒前
cdercder应助科研通管家采纳,获得10
58秒前
阿托品完成签到 ,获得积分10
58秒前
山山而川完成签到,获得积分10
1分钟前
祥子完成签到,获得积分10
1分钟前
1分钟前
SDNUDRUG发布了新的文献求助10
1分钟前
冷酷的闹闹完成签到 ,获得积分10
1分钟前
周冯雪完成签到 ,获得积分10
1分钟前
fang完成签到,获得积分10
1分钟前
wenhuanwenxian完成签到 ,获得积分10
1分钟前
1分钟前
糖宝完成签到 ,获得积分10
1分钟前
minuxSCI完成签到,获得积分10
1分钟前
winew完成签到 ,获得积分10
1分钟前
1分钟前
妮妮发布了新的文献求助10
1分钟前
ybwei2008_163发布了新的文献求助10
2分钟前
狼来了aas完成签到,获得积分10
2分钟前
hanhan完成签到 ,获得积分10
2分钟前
HHHWJ完成签到 ,获得积分10
2分钟前
科研通AI5应助wwqing0704采纳,获得10
2分钟前
2分钟前
kenchilie完成签到 ,获得积分10
2分钟前
wwqing0704发布了新的文献求助10
2分钟前
高分求助中
【此为提示信息,请勿应助】请按要求发布求助,避免被关 20000
Technologies supporting mass customization of apparel: A pilot project 450
Mixing the elements of mass customisation 360
Периодизация спортивной тренировки. Общая теория и её практическое применение 310
the MD Anderson Surgical Oncology Manual, Seventh Edition 300
Nucleophilic substitution in azasydnone-modified dinitroanisoles 300
Political Ideologies Their Origins and Impact 13th Edition 260
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 物理 生物化学 纳米技术 计算机科学 化学工程 内科学 复合材料 物理化学 电极 遗传学 量子力学 基因 冶金 催化作用
热门帖子
关注 科研通微信公众号,转发送积分 3780865
求助须知:如何正确求助?哪些是违规求助? 3326359
关于积分的说明 10226680
捐赠科研通 3041524
什么是DOI,文献DOI怎么找? 1669502
邀请新用户注册赠送积分活动 799075
科研通“疑难数据库(出版商)”最低求助积分说明 758732