• Title/Summary/Keyword: Performance Counter Monitor

Search Result 11, Processing Time 0.025 seconds

Real-Time Detection on FLUSH+RELOAD Attack Using Performance Counter Monitor (Performance Counter Monitor를 이용한 FLUSH+RELOAD 공격 실시간 탐지 기법)

  • Cho, Jonghyeon;Kim, Taehyun;Shin, Youngjoo
    • KIPS Transactions on Computer and Communication Systems
    • /
    • v.8 no.6
    • /
    • pp.151-158
    • /
    • 2019
  • FLUSH+RELOAD attack exposes the most serious security threat among cache side channel attacks due to its high resolution and low noise. This attack is exploited by a variety of malicious programs that attempt to leak sensitive information. In order to prevent such information leakage, it is necessary to detect FLUSH+RELOAD attack in real time. In this paper, we propose a novel run-time detection technique for FLUSH+RELOAD attack by utilizing PCM (Performance Counter Monitor) of processors. For this, we conducted four kinds of experiments to observe the variation of each counter value of PCM during the execution of the attack. As a result, we found that it is possible to detect the attack by exploiting three kinds of important factors. Then, we constructed a detection algorithm based on the experimental results. Our algorithm utilizes machine learning techniques including a logistic regression and ANN(Artificial Neural Network) to learn from different execution environments. Evaluation shows that the algorithm successfully detects all kinds of attacks with relatively low false rate.

Machine Learning-Based Detection of Cache Side Channel Attack Using Performance Counter Monitor of CPU (Performance Counter Monitor를 이용한 머신 러닝 기반 캐시 부채널 공격 탐지)

  • Hwang, Jongbae;Bae, Daehyeon;Ha, Jaecheol
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.30 no.6
    • /
    • pp.1237-1246
    • /
    • 2020
  • Recently, several cache side channel attacks have been proposed to extract secret information by exploiting design flaws of the microarchitecture. The Flush+Reload attack, one of the cache side channel attack, can be applied to malicious application attacks due to its properties of high resolution and low noise. In this paper, we proposed a detection system, which detects the cache-based attacks using the PCM(Performance Counter Monitor) for monitoring CPU cache activity. Especially, we observed the variation of each counter value of PCM in case of two kinds of attacks, Spectre attack and secret recovering attack during AES encryption. As a result, we found that four hardware counters were sensitive to cache side channel attacks. Our detector based on machine learning including SVM(Support Vector Machine), RF(Random Forest) and MLP(Multi Level Perceptron) can detect the cache side channel attacks with high detection accuracy.

Exploring Branch Target Buffer Architecture on Intel Processors with Performance Monitor Counter (Performance Monitor Counter를 이용한 Intel Processor의 Branch Target Buffer 구조 탐구)

  • Jeong, Juhye;Kim, Han-Yee;Suh, Taeweon
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2019.10a
    • /
    • pp.24-27
    • /
    • 2019
  • Meltdown, Spectre 등 하드웨어의 취약점을 이용하는 side-channel 공격이 주목을 받으면서 주요 microarchitecture 구조에 대한 철저한 이해의 필요성이 커지고 있다. 현대 마이크로프로세서에서 branch prediction이 갖는 중요성에도 불구하고 세부적인 사항은 거의 알려지지 않았으며 잠재적 공격에 대비하기 위해서는 반드시 현재 드러난 정보 이상의 detail을 탐구하기 위한 시도가 필요하다. 본 연구에서는 Performance Monitor Counter를 이용해 branch 명령어를 포함한 프로그램이 실행되는 동안 Branch Prediction Unit에 의한 misprediction 이벤트가 발생하는 횟수를 체크하여 인텔 하스웰, 스카이레이크에서 사용되는 branch target buffer의 구조를 파악하기 위한 실험을 수행하였다. 연구를 통해 해당 프로세서의 BTB의 size, number of way를 추정할 수 있었다.

Real-time detection on FLUSH+RELOAD attack using Performance Counter Monitor (Performance Counter Monitor 를 이용한 FLUSH+RELOAD 공격 실시간 탐지 기술)

  • Cho, Jong-Hyeon;Kim, Tae-Hyun;Shin, Youngjoo
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2018.10a
    • /
    • pp.166-169
    • /
    • 2018
  • 캐시 부채널 공격 중 하나인 FLUSH+RELOAD 공격은 높은 해상도와 적은 오류로 그 위험성이 높고, 여러가지 프로그램에서도 적용되어 개인정보의 유출에 대한 위험성까지 증명 되었다. 따라서 이 공격을 막기 위해 실시간으로 감지 할 수 있어야 할 필요성이 있다. 본 연구에서는 4가지 실험을 통하여 이 FLUSH+RELOAD 공격을 받을 때 PCM(Performance Counter Monitor)를 사용해 각각의 counter들의 값의 변화를 관찰하여 3가지 중요한 요인에 의해 공격 탐지를 할 수 있다는 것을 발견하였다. 이를 이용하여 머신 러닝의 logistic regression과 ANN(Artificial Neural Network)를 사용해 결과에 대한 각각 학습을 시킨 뒤, 실시간으로 공격에 대한 탐지를 할 수 있는 프로그램을 제작하였다. 일정한 시간동안 공격을 진행하여 모든 공격을 감지하는데 성공하였고, 상대적으로 적은 오탐률을 보여주었다.

Performance Comparison of Bed-type and Stand-type Commercial Whole Body Counter Made by Canberra for Internal Exposure Monitoring (Bed-type과 Stand-type 상용 전신계수기(Whole Body Counter)의 성능 비교)

  • Kim, Bong-Gi;Ha, Wi-ho;Kwon, Tae-Eun;Park, Min-Seok;Lee, Jun-Ho;Kim, Jong-Min;Lee, Sang-Gyung;Jung, Kyu-Hwan
    • Journal of radiological science and technology
    • /
    • v.41 no.5
    • /
    • pp.437-444
    • /
    • 2018
  • Whole-Body counters have been used to evaluate the internal contamination of gamma emitting radionuclides. Among the whole-body counters used in domestic nuclear facilities, Fastscan made by CANBERRA contains 2 NaI(Tl) detectors and is generally used to monitor the primary internal exposure. It has the advantage of achieving MDA even with short time measurements. Accuscan is a bed type, and has good energy resolution because it is composed of HPGe detector. Since the Accuscan with better energy resolution than Fastscan has better able to identify radionuclides, it is used to monitor secondary internal exposure. Some nuclear facilities have only Fastscan. We analyzed statistically whether Fastscan is enough to ensure accuracy and precision comparing with Accuscan. To do this, we prepared a CRM created by the Korea Research Institute of Standards and Science. We also obtained the data of 6 Fastscans and 5 Accuscans in domestic nuclear facilities. As a result of the study, although Fastscan compared with Accuscan is not as accurate as the Accuscan, the precision is statistically same. However, accuracy of Fastscan is in compliance with international standards except low energy range. In terms of accuracy and precision except radionuclides emitting low energy, it is possible to measure radioactivity inside workers even in nuclear facilities where only Fastscan is used.

A Case Study for Improving Performance of A Banking System Using Load Test (부하테스트를 이용한 금융 시스템의 성능개선 사례)

  • Kim, Tai Suk;Lee, Jong Yun;Kim, Jong Soo
    • Journal of Korea Multimedia Society
    • /
    • v.18 no.12
    • /
    • pp.1501-1508
    • /
    • 2015
  • In this paper, we describe a case study to improve performance through the load testing of multi-tired system for financial accounts before the system opening. The load test was conducted after the data collection tools(Performance Monitor, DB PSSDiag) were installed. By analyzing the collected log, we were able to identify the main sector requiring performance improvements among the presentation tier, web tier, business logic tier and data tier. The ASP.NET server-down on the web tier could be improved by modifying the parameter values in the configuration file. Some server downs occurred on the business logic tier when a large number of users access at the same time, were more difficult to be solved. By analyzing the hang-dump at the server-down time, we were able to find a process that caused the problem. and we had to modify the relevant codes. For major performance improvements of the data-tier, indices of some queries was optimized by using the built-in DBMS query analyzer, after analyzing the log of long-response-time queries. The problems and solutions considered in this case study will be a reference for the performance improvement of a multi-layer system with the similar structure.

Preparation of an Inorganic Scintillator Loaded Film for the Measurement of Surface Contamination and its Performance Test (표면오염 측정용 무기섬광 함침 필름의 제조 및 성능 평가)

  • 서범경;이근우;임난주;박진호;한명진
    • Journal of Energy Engineering
    • /
    • v.13 no.2
    • /
    • pp.93-100
    • /
    • 2004
  • The smear media possible to sampling and radiation detection was prepared and evaluated for the surface contamination using indirect method. The films were made by impregnating Cerium Activated Yttrium Silicate (CAYS) in a polysulfone membrane. The membranes used solution as a dimethylformamide (DMF) and methylene chloride (MC), polysulfone as a polymer matrix and CAYS as a inorganic scintillator. The proximity membranes were prepared with single- and double-layered structure. The solidified methods were immersion to the nonsolvent bath such at water and ethanol and solvent evaporation. The measurement of the photon produced by interaction with radiation and inorganic scintillator used a photomultiflier tube (PMT), amplifier, and counter. In the comparison with the low background alpha/beta counter, the counter rate using inorganic scintillator proximity membrane for the $\^$14/C surface contamination was about 50%. Also. the $^3$H counting results revealed that the prepared membranes were efficient to monitor the surface contaminated with the low energy be-ray emitter nuclides.

Fabrication and Characteristics of Amperometric NO2 Gas Sensors (전류검출형 NO2가스 센서의 제작과 특성평가)

  • Kim, Gwi-Yeol
    • Journal of the Korean Institute of Electrical and Electronic Material Engineers
    • /
    • v.20 no.9
    • /
    • pp.821-827
    • /
    • 2007
  • The nitrogen oxides, NO and $NO_2$, abbreviated usually as NOx, emitted from combustion facilities such as power plants and automobiles are the typical air-pollutants causing acid rain and photochemical smog. In order to solve the NOx-related pollution problems effectively, we need efficient techniques to monitor NOx in the combustion exhausts and in environments. Development of solid-state electrochemical devices for detecting NOx is demonstrated based on various combination of solid electrolytes and auxiliary sensing materials. The object of this research is to develop various sensor performance for solid state amperometric sensor, and to test gas sensor performance manufactured. So we try to present a guidance for developing amperometric gas sensor. We concentrated on development of manufacturing process and performance test. Amperometric Nitrogen dioxide sensor was fabricated using NASICON and an $NaNO_2$ layer deposited on the counter electrode. The current response was almost linear with Nitrogen dioxide concentration in the range 1-350 ppb at $150^{\circ}C$.

SIMULATION OF THE TISSUE EQUIVALENT PROPORTIONAL COUNTER IN THE INTERNATIONAL SPACE STATION WITH GEANT4 (Geant4를 활용한 국제우주정거장 내의 조직등가비례계수기 모의 실험)

  • Pyo, Jeong-Hyun;Lee, Jae-Jin;Nam, Uk-Won;Kim, Sung-Hwan;Kim, Hyun-Ok;Lim, Chang-Hwy;Park, Kwi-Jong;Lee, Dae-Hee;Park, Young-Sik;Moon, Myung-Kook
    • Publications of The Korean Astronomical Society
    • /
    • v.27 no.3
    • /
    • pp.81-86
    • /
    • 2012
  • The International Space Station (ISS) orbits the Earth within the inner radiation belt, where high-energy protons are produced by collisions of cosmic rays to the upper atmosphere. About 6 astronauts stay in the ISS for a long period, and it should be important to monitor and assess the radiation environment in the ISS. The tissue equivalent proportional counter (TEPC) is an instrument to measure the impact of radiation on the human tissue. KASI is developing a TEPC as a candidate payload of the ISS. Before the detailed design of the TEPC, we performed simulations to test whether our conceptual design of the TEPC will work propertly in the ISS and to predict its performance. The simulations estimated that the TEPC will measure the dose equivalent of about 1:1 mSv during a day in the ISS, which is consistent with previous measurements.

Development of Neutron, Gamma ray, X-ray Radiation Measurement and Integrated Control System (중성자, 감마선, 엑스선 방사선 측정 및 통합 제어 시스템 개발)

  • Ko, Tae-Young;Lee, Joo-Hyun;Lee, Seung-Ho
    • Journal of IKEEE
    • /
    • v.21 no.4
    • /
    • pp.408-411
    • /
    • 2017
  • In this paper, we propose an integrated control system that measures neutrons, gamma ray, and x-ray. The proposed system is able to monitor and control the data measured and analyzed on the remote or network, and can monitor and control the status of each part of the system remotely without remote control. The proposed system consists of a gamma ray/x-ray sensor part, a neutron sensor part, a main control embedded system part, a dedicated display device and GUI part, and a remote UI part. The gamma ray/x-ray sensor part measures gamma ray and x-ray of low level by using NaI(Tl) scintillation detector. The neutron sensor part measures neutrons using Proportional Counter Detector(low-level neutron) and Ion Chamber Type Detector(high-level neutron). The main control embedded system part detects radiation, samples it in seconds, and converts it into radiation dose for accumulated pulse and current values. The dedicated display device and the GUI part output the radiation measurement result and the converted radiation amount and radiation amount measurement value and provide the user with the control condition setting and the calibration function for the detection part. The remote UI unit collects and stores the measured values and transmits them to the remote monitoring system. In order to evaluate the performance of the proposed system, the measurement uncertainty of the neutron detector was measured to less than ${\pm}8.2%$ and the gamma ray and x-ray detector had the uncertainty of less than 7.5%. It was confirmed that the normal operation was not less than ${\pm}15$ percent of the international standard.