Beilei Zheng

dblp:246/8770 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
2since 2021 · last 2022
0000-0002-7196-9711ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2022 Outlier: Enabling Effective Measurement of Hypervisor Code Integrity With Group Detection
abstract
Virtualization brings the benefits of utilization and scalability to the multi-tenant cloud platforms. However, the hypervisor, as one of the foundations in virtualization, is challenging to survive under various malicious attacks due to its large attack surface. This article presents a novel group detection framework for the hypervisor code integrity, called Outlier . In an Outlier group, each host contains two parts. One is a distributed detection protocol, called Co-protocol , and the other is a detection interface, called Checker . The Co-protocol constructs trust for the integrity detection within an Outlier group. With the Co-protocol, each Checker conducts reliable integrity detection on the hypervisor code, and then the potential “outlier” host is perceived. We implement our Outlier prototype on the Xen hypervisor and evaluate its overhead. Experiments show that the introduction of the Outlier has few impacts on the performance of the virtualized systems.
Jianan Gu, Beilei Zheng, Chuliang Weng
IEEE Trans. Dependable Secur. Comput.3
2022 CBA-Detector: A Self-Feedback Detector Against Cache-Based Attacks
abstract
Cloud computing is convenient to provide adequate resources for tenants. However, since multiple tenants share the underlying hardware resources, malicious tenants can use the shared processor to launch cache-based attacks. Such attacks can help malicious tenants steal private data of other tenants bypassing isolation mechanisms provided by the system, resulting in information leakage. Moreover, Spectre and Meltdown vulnerabilities can even extract memory contents arbitrarily with the help of cache attacks. Therefore, cache-based attacks pose a serious threat to the security of cloud platforms. To defeat such attacks, many detection methods have been proposed. However, most methods induce high false positives because they completely rely on the hardware performance counters (HPCs) and detect attacks with static criteria. To solve this problem, this article proposes a self-feedback detector named CBA-Detector to detect cache-based attacks in real time. Specifically, CBA-Detector first uses machine learning technologies to create models for identifying suspicious programs with abnormal hardware behaviors, then analyzes suspicious programs from the instruction level to identify real attacks and provide feedback. Based on the feedback, the models can be updated to further improve their detection accuracy. As our experiments show, CBA-Detector can accurately identify cache-based attacks in real time and introduces a little overhead. Besides, the misjudgment rate decreases with the running time.
Beilei Zheng, Jianan Gu, Jialun Wang, Chuliang Weng
IEEE Trans. Dependable Secur. Comput.1
2019 CBA-Detector: An Accurate Detector Against Cache-Based Attacks Using HPCs and Pintools
Beilei Zheng, Jianan Gu, Chuliang Weng
APPT1
2019 Interleaved Multi-Vectorizing
abstract
SIMD is an instruction set in mainstream processors, which provides the data level parallelism to accelerate the performance of applications. However, its advantages diminish when applications suffer from heavy cache misses. To eliminate cache misses in SIMD vectorization, we present interleaved multi-vectorizing (IMV) in this paper. It interleaves multiple execution instances of vectorized code to hide memory access latency with more computation. We also propose residual vectorized states to solve the control flow divergence in vectorization. IMV can make full use of the data parallelism in SIMD and the memory level parallelism through prefetching. It reduces cache misses, branch misses and computation overhead to significantly speed up the performance of pointer-chasing applications, and it can be applied to executing entire query pipelines. As experimental results show, IMV achieves up to 4.23X and 3.17X better performance compared with the pure scalar implementation and the pure SIMD vectorization, respectively.
Zhuhe Fang, Beilei Zheng, Chuliang Weng
Proc. VLDB Endow.2