µRAI: Securing Embedded Systems with Return Address Integrity
Naif Saleh Almakhdhub, Abraham A. Clements, Saurabh Bagchi, Mathias Payer
Abstract
Embedded systems are deployed in security critical environments and have become a prominent target for remote attacks. Microcontroller-based systems (MCUS) are particularly vulnerable due to a combination of limited resources and low level programming which leads to bugs. Since MCUS are often a part of larger systems, vulnerabilities may jeopardize not just the security of the device itself but that of other systems as well. For example, exploiting a WiFi System on Chip (SoC) allows an attacker to hijack the smart phone’s application processor. Control-flow hijacking targeting the backward edge (e.g., Return-Oriented Programming–ROP) remains a threat for MCUS. Current defenses are either susceptible to ROP-style attacks or require special hardware such as a Trusted Execution Environment (TEE) that is not commonly available on MCUS. We present μRAI , a compiler-based mitigation to prevent control-flow hijacking attacks targeting backward edges by enforcing the Return Address Integrity (RAI) property on MCUS. μRAI does not require any additional hardware such as TEE, making it applicable to the wide majority of MCUS. To achieve this, μRAI introduces a technique that moves return addresses from writable memory, to readable and executable memory. It repurposes a single general purpose register that is never spilled, and uses it to resolve the correct return location. We evaluate against the different control-flow hijacking attacks scenarios targeting return addresses (e.g., arbitrary write), and demonstrate how μRAI prevents them all. Moreover, our evaluation shows that μRAI enforces its protection with negligible overhead.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8cd76093-58d8-4c41-a220-7b90c555ded4Cited by top-tier papers13
- SHERLOC: Secure and Holistic Control-Flow Violation Detection on Embedded SystemsXi Tan, Ziming ZhaoCCS 2023 · 13 citations
- On Bridging the Gap between Control Flow Integrity and Attestation SchemesMahmoud Ammar, Ahmed Abdelraoof, Silviu VlasceanuUSENIX Security 2024 · 9 citations
- SoK: Integrity, Attestation, and Auditing of Program ExecutionMahmoud Ammar, Adam Caulfield, Ivan De Oliveira NunesS&P 2025
- Silhouette: Efficient Protected Shadow Stacks for Embedded SystemsJie Zhou, Yufei Du, Zhuojia Shen, Lele Ma et al.USENIX Security 2020
- PEARTS: Provable Execution in Real-Time Embedded SystemsAntonio Joia Neto, Norrathep Rattanavipanon, Ivan De Oliveira NunesS&P 2025
Builds on13
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- C-FLAT: Control-Flow Attestation for Embedded Systems SoftwareTigist Abera, N. Asokan, Lucas Davi, Jan-Erik Ekberg et al.CCS 2016 · 311 citations
- A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary LevelVictor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski et al.S&P 2016 · 227 citations
- Enforcing Unique Code Target Property for Control-Flow IntegrityHong Hu, Chenxiong Qian, Carter Yagemann, Simon Pak Ho Chung et al.CCS 2018 · 142 citations
Related papers
- OAT: Attesting Operation Integrity of Embedded DevicesZhichuang Sun, Bo Feng, Long Lu, Somesh JhaS&P 2020 · 89 citations
- Protecting Bare-Metal Embedded Systems with Privilege OverlaysAbraham A. Clements, Naif Saleh Almakhdhub, Khaled Saab, Prashast Srivastava et al.S&P 2017 · 122 citations
- SpecCFI: Mitigating Spectre Attacks using CFI Informed SpeculationEsmaeil Mohammadian Koruyeh, Shirin Haji Amin Shirazi, Khaled N. Khasawneh, Chengyu Song et al.S&P 2020 · 74 citations
- ACFA: Secure Runtime Auditing & Guaranteed Device Healing via Active Control Flow AttestationAdam Caulfield, Norrathep Rattanavipanon, Ivan De Oliveira NunesUSENIX Security 2023
- XCFI: Comprehensive Control-Flow Integrity for Arm TrustZone-MYunju Gu, Jaeyeol Park, Donghyun KwonUSENIX Security 2026
