Software platforms like endpoint detection and response (EDR) play an important role in combatting cyberthreats, but what if they could take advantage of the underlying silicon? That’s a question at the top of Intel Business Client Director Mike Nordquist’s mind.
He believes silicon has a role to play in protecting users from the next wave of cyber threats.
The idea of implementing security features at the silicon level is nothing new for Intel. In the wake of the Spectre and Meltdown vulnerabilities, Intel announced new mitigations in collaboration with Microsoft and Cisco that used the chip’s integrated GPU to accelerate memory scanning and offload virus detection on chips affected by the exploits.
In the four years since, Intel has hardened its chips against side-channel attacks as the principle of silicon-accelerated security has gained momentum.
The next question was: “What can we do for some of the EDR vendors,” Nordquist said. “We're not going out there and saying we’re going to displace CrowdStrike or Defender, or any of those people.”
Instead, Intel sees an opportunity to accelerate security functionality like machine learning and cryptography and help EDR platforms identify threats faster and more accurately. “If there's no easy way for end users or IT shops to take advantage, they won’t,” Nordquist said.
With Intel’s 11th-generation client CPUs, codenamed Tiger Lake, the company’s Threat Detection Technology (TDT) gained the ability to detect and flag cryptomining and ransomware attacks.
The functionality enables EDR and other security platforms to more efficiently and accurately access and mitigate threats than would be possible through software alone, Nordquist said. For example, if Intel’s CPUs detect an encryption workload — a tell-tale sign of a ransomware attack — it’ll flag it for closer inspection by an EDR service.
Intel Beats Back Control-Flow AttacksNordquist argues that in some cases, it's actually easier to mitigate threats in silicon than it is in the software. One such example is control-flow attacks.
“There's certain things they [software vendors] can't solve even if they wanted to. CET is a great example. I know they tried for years to solve control-flow attacks in this space, and they just kept finding ways they can circumvent it,” he said, referring to Intel’s Control-Flow Enforcement Technology (CET), also introduced with Tiger Lake.
CET is designed to mitigate a pervasive threat called return-oriented programming attacks, in which code already running in system memory is combined to achieve a malicious result. Because the code appears to be legitimate, these attacks can be incredibly difficult to detect.
These attacks were “not detectable with any solutions that were in the market,” explained Tom Garrison, VP and GM of client security strategy at Intel, in an earlier discussion.
However, by detecting them at the silicon level, Intel says it can successfully mitigate return-oriented programming attacks.
Meanwhile, Intel constantly reevaluates where it should go next with silicon-level mitigations based on the chipmaker’s threat intelligence and bug bounty programs, Nordquist explained. “Our challenge is always innovating to find the next thing.”
Client-Side Confidential ComputingOne opportunity could involve bringing confidential computing principles to the client space.
Confidential computing involves encrypting data while at rest, in transit, and — critically — while in use, and it's gained considerable traction in recent years as public cloud providers have grown increasingly security conscious.
The technology is especially attractive for organizations that handle sensitive data such as personally identifiable information, financial data, or health-care records, and thus need to mitigate threats that target the confidentiality and integrity of the applications and data in system memory.
While Nordquist said there doesn’t appear to be the same pressure to apply confidential computing in the client space yet, that’s not to say he can’t see why someone might want to. He described a scenario in which an enterprise might want to deploy a virtual machine on a gig worker’s PC to isolate the data from the rest of the system in a way that can be revoked once the job is done.
However, when the technology will make its way to client space in earnest remains to be seen, he said. “I’m trying to figure out is that in two years, is that in five years.”
Intel isn’t the only chip company exploring this possibility either. Arm, earlier this year, announced the Confidential Compute Architecture (CCA) alongside its ARMv9 microarchitecture.
CCA is Arm’s take on confidential computing. But unlike Intel and AMD, which have focused their attention on the data center and cloud, Arm is taking a more generalized approach. “This is intended to be an architecture for all markets spanning cloud to mobile and automotive to IoT,” said Mark Knight, director of architecture products at Arm, in an earlier interview.
Comments