PolyRhythm: Adaptive Tuning of a Multi-Channel Attack Template for Timing Interference
Ao Li, Marion Sudvarg, Han Liu, Zhiyuan Yu, Chris Gill, Ning Zhang
Abstract
As cyber-physical systems have become increasingly complex, rising computational demand has led to the ubiquitous use of multicore processors in embedded environments. Size, Weight, Power, and Cost (SWaP-C) constraints have pushed more processes onto shared platforms, including real-time tasks with deadline requirements. To prevent temporal interference among tasks running concurrently or in parallel in such systems, many operating systems provide priority-based scheduling and enforce processor reservations based on Worst-Case Execution Time (WCET) estimates. However, shared resources (both architectural components and data structures within the operating system) provide channels through which these constraints can be broken. Prior work has demonstrated that malicious execution by one or more processes can cause significant delays, leading to potential deadline misses in victim tasks. In this paper, we introduce PolyRhythm, a three-phase attack template that combines primitives across multiple architectural and kernel-based channels: (1) it uses an offline genetic algorithm to tune attack parameters based on the target hardware and OS platform; then (2) it performs an online search for regions of the attack parameter space where contention is most likely; and finally (3) it runs the attack primitives, using online reinforcement learning to adapt to dynamic execution patterns in the victim task. On a representative platform (Raspberry Pi 3B) Poly Rhythm outperforms prior work, achieving significantly more slowdown. As we show for several hardware/software platforms, Poly Rhythm also allows us to characterize the extent to which interference can occur; this helps to inform better estimates of execution times and overheads, towards preventing deadline misses in real-time systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 15af68c0-5aec-4bfd-a67f-c0d07c77e281Cited by top-tier papers8
- Data-flow Availability: Achieving Timing Assurance in Autonomous SystemsAo Li, Ning ZhangOSDI 2024 · 10 citations
- Opportunistic Data Flow Integrity for Real-time Cyber-physical Systems Using Worst Case Execution Time ReservationYujie Wang, Ao Li, Jinwen Wang, Sanjoy K. Baruah et al.USENIX Security 2024 · 8 citations
- Per-Bank Bandwidth Regulation of Shared Last-Level Cache for Real-Time SystemsConnor Sullivan, Alex Manley, Mohammad Alian, Heechul YunRTSS 2024 · 4 citations
- PhySense: Defending Physically Realizable Attacks for Autonomous Systems via Consistency ReasoningZhiyuan Yu, Ao Li, Ruoyao Wen, Yijia Chen et al.CCS 2024 · 4 citations
- Subtask-Level Elastic SchedulingMarion Sudvarg, Daisy Wang, Jeremy Buhler, Chris GillRTSS 2024 · 1 citation
Builds on4
- FIRM: An Intelligent Fine-grained Resource Management Framework for SLO-Oriented MicroservicesHaoran Qiu, Subho S. Banerjee, Saurabh Jha, Zbigniew T. Kalbarczyk et al.OSDI 2020 · 350 citations
- Theory and Practice of Finding Eviction SetsPepe Vila, Boris Köpf, José F. MoralesS&P 2019 · 145 citations
- RT-TEE: Real-time System Availability for Cyber-physical Systems using ARM TrustZoneJinwen Wang, Ao Li, Haoran Li, Chenyang Lu et al.S&P 2022 · 69 citations
- D3: a dynamic deadline-driven approach for building autonomous vehiclesIonel Gog, Sukrit Kalra, Peter Schafhalter, Joseph E. Gonzalez et al.EuroSys 2022 · 39 citations
Related papers
- Catch Me If You Learn: Real-Time Attack Detection and Mitigation in Learning Enabled CPSIpsita Koley, Sunandan Adhikary, Soumyajit DeyRTSS 2021 · 8 citations
- Repttack: Exploiting Cloud Schedulers to Guide Co-Location AttacksChongzhou Fang, Han Wang, Najmeh Nazari, Behnam Omidi et al.NDSS 2022
- Interference-free Operating System: A 6 Years' Experience in Mitigating Cross-Core Interference in LinuxZhaomeng Deng, Ziqi Zhang, Ding Li, Yao Guo et al.RTSS 2024 · 6 citations
- Precise and scalable shared cache contention analysis for WCET estimationWei Zhang, Mingsong Lv, Wanli Chang, Lei JuDAC 2022 · 12 citations
- Partial Context-Sensitive Pointer Integrity for Real-time Embedded SystemsYujie Wang, Cailani Lemieux Mack, Thidapat Chantem, Sanjoy K. Baruah et al.RTSS 2024 · 3 citations
