Hardware-based Real-time Workload Forensics via Frame-level TLB Profiling
Yunjie Zhang, Liwei Zhou, Yiorgos Makris · 2019
We propose a hardware-based solution for performing real-time workload forensics that enables identification of a process while it is being executed. More specifically, we divide execution flow of a process into consecutive frames and we extract descriptive features related to the Translation Lookaside Buffer (TLB) utilization profile for each such frame. These features are then processed through trained machine learning models to analyze program behavior and identify workload at the granularity of a process. Unlike previous research on workload forensics that performs ex post facto analysis based on the complete process execution profile, this method continuously analyzes the segmented workload execution flow; thus, it does not require knowledge of process creation, switch, and termination timestamps. Furthermore, as compared with software-based workload forensics solutions, whose data logging mechanism may be compromised by software attacks, the proposed hardware-based logging mechanism does not rely on services from the operating system (OS) or high-level applications and is, therefore, inherently immune to software tampering. The proposed workload forensics method was evaluated using a Linux OS loaded on Spike, an open-source RISC-V simulator. Experimental results using the Mibench benchmark suite indicate an overall identification accuracy of 98.9% with practicable logging overhead.