Organisational Resilience to GPU Side-Channel Attacks: NIST 2.0 on Risk Management and Governance Strategies Assessment
Author: Nelson Lungu*, Simon Tembo, Charles Lubobya
Electrical and Electronical Engineering, University of Zambia, Lusaka, Zambia.
Published Date: 2024-10-06
Keywords: Graphics processing units security, side-channel attacks, risk management, timing analysis, power analysis.
Abstract:
Organisational resilience to GPU side-channel attacks has surfaced as a pressing requirement with the advent of high-performance computing and data-intensive applications. The increasing adoption of GPUs necessitates commensurate cybersecurity mechanisms to protect sensitive information and assure the proper functioning of computing components. This work investigates the implications of NIST’s Cybersecurity Framework 2.0 within risk management and governance considering GPU side-channel attacks. We provide an overview of prevalent threats against GPU accelerator systems in terms of timing attacks, power analysis as well as cache attacks. Subsequently, a dependable, secure shader execution architecture is specified based on current state-of-the-art solutions augmented by advanced mathematical formulas exploited to reduce risks caused by GPU side-channel attacks in practice. In this context, we show that resilience can be reached, especially when risk-aware management is combined with adaptive governance measures derived from NIST’s Cybersecurity Framework 2.0, processing regular updates quarterly or even more frequently using our methodology.
