Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud Security

4/19/2018
08:05 AM
Jeffrey Burt
Jeffrey Burt
Jeffrey Burt
50%
50%

In Wake of Spectre & Meltdown, Intel Shifts Memory Scanning to GPU

At the RSA Conference this week, Intel introduced several silicon-level security technologies, including moving memory scanning from the CPU to the GPU, as part of its larger 'security-first' strategy following the Spectre and Meltdown issues.

The Spectre and Meltdown side-channel security flaws that became public in January and shook the processor industry put a bullseye on Intel more than other chipmakers and forced the company to take the lead in addressing the need for greater security measures at the silicon level.

After initial stumbles, Intel issued a series of patches and microcode to address the vulnerabilities in its microprocessors that were discovered by Google, and at the CES 2018 show that month and in a couple of open letters issued later, CEO Brian Krzanich promised a "security-first" approach for the company's chips. (See Intel Will Leave Some Chips Without Spectre Patch.)

That silicon-level security approach has been evident this week in a series of announcements the chip maker made at the RSA 2018 Conference in San Francisco.

Among the new technologies Intel introduced was its Threat Detection Technology, designed to help systems more quickly detect advanced cyber threats, and included Accelerated Memory Scanning, which offloads the compute-intensive job of scanning for memory-based threats from the CPU to an integrated GPU.

The move is designed to improve the capability of systems to detect such exploits while significantly reducing the heavy tax on the performance and power consumption of the CPU cores. Early benchmarks of the technology showed CPU utilization dropping from 20% to a little as 2%, Rick Echevarria, vice president of Intel's Software and Services Group and general manager of its Platforms Security Division, wrote in a post on the company blog.

Microsoft officials said the software maker is integrating the Accelerated Memory Scanning technology into the antivirus capability of its Microsoft Windows Defender Advanced Threat Protection (ATP) offering in systems running on Intel's 6th-, 7th- and 8th-generation Core processors.

Intel's decision to move memory scanning to GPUs makes sense, Patrick Moorhead, principal analyst with Moor Insights and Strategy, told Security Now in an email.

"GPUs are best at very highly parallelized, simple tasks and this is exactly what memory scanning are all about," Moorhead wrote, adding that it will deliver "a huge improvement over CPU-only. This demonstrates that Intel is choosing security over pushing CPU performance. Intel for years was an 'x86 CPU' house and pretty much all roads led to a CPU. Now with the Altera, Nervana, Movidius and MobilEye acquisitions, times are changing as Intel has embraced heterogeneous computing. Intel could have chosen not to offload the very capable CPU over a GPU, but instead chose the best technical solution to better secure the platform."

Intel's security push
Another part of the Threat Detection Technology introduction was Advanced Platform Telemetry, which draws on machine learning algorithms with platform telemetry to not only improve the detection of advanced threats but also reduce false positives and reduce the impact on system performance.

Cisco is putting the technology into its Tetration data center and cloud security platform for systems powered by Intel's Skylake Xeon Scalable Processors.

Intel also launched Intel Security Essentials, which are designed to drive a consistent set of root-of-trust hardware security capabilities across Intel's Core, Intel Xeon and Intel Atom processor platforms.


The fundamentals of network security are being redefined -- don't get left in the dark by a DDoS attack! Join us in Austin from May 14-16 at the fifth annual Big Communications Event. There's still time to register and communications service providers get in free!

"These capabilities are platform integrity technologies for secure boot, hardware protections (for data, keys and other digital assets), accelerated cryptography and trusted execution enclaves to protect applications at runtime," Echevarria wrote in his blog post. "This standard set of capabilities will accelerate trusted computing as customers build solutions rooted in hardware-based protections."

Moorhead noted that the partnerships with vendors such as Microsoft and Cisco are important in security, where the more data a company has to work with, the quicker the industry as a whole can address and prevent issues before damage is done.

The analyst also applauded Intel's response to the Spectre and Meltdown vulnerabilities, particularly given that it was Intel that was first linked to the security flaws, even though they impacted competitors as well. Essentially, by exploiting the flaws in the chips, hackers can access the operating system's kernel memory.

The weak link is the way the chips handle "speculative execution," which is done to increase performance by predicting the path of a particular task to find the fastest way to complete it.

"It affected Arm, AMD and Intel, yet Intel took the brunt of the public scorn," Moorhead wrote. "Intel then over-communicated to a fault, which thrust them again and again into the spotlight. They also communicated on behalf of other companies like Apple, Microsoft Azure, and GCP [Google Cloud Platform]. Note there have been no verified attacks or damage done. The final impactful thing Intel did was to form a division, reporting into [Krzanich], that can throw yellow flags and delay architectures and products. This is a big deal."

Related posts:

— Jeffrey Burt is a long-time tech journalist whose work has appeared in such publications as eWEEK, The Next Platform and Channelnomics.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/6/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Another COVID-19 Side Effect: Rising Nation-State Cyber Activity
Stephen Ward, VP, ThreatConnect,  7/1/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15600
PUBLISHED: 2020-07-07
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
CVE-2020-15599
PUBLISHED: 2020-07-07
Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.
CVE-2020-8916
PUBLISHED: 2020-07-07
A memory leak in Openthread's wpantund versions up to commit 0e5d1601febb869f583e944785e5685c6c747be7, when used in an environment where wpanctl is directly interfacing with the control driver (eg: debug environments) can allow an attacker to crash the service (DoS). We recommend updating, or to res...
CVE-2020-12821
PUBLISHED: 2020-07-07
Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.
CVE-2020-15008
PUBLISHED: 2020-07-07
A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and utilizes the user su...