Silhouette: Efficient Protected Shadow Stacks for Embedded Systems
Jie Zhou, Yufei Du, Zhuojia Shen, Lele Ma, John Criswell, Robert J. Walls
摘要
Microcontroller-based embedded systems are increasingly used for applications that can have serious and immediate consequences if compromised-including automobile control systems, smart locks, drones, and implantable medical devices. Due to resource and execution-time constraints, C is the primary language used for programming these devices. Unfortunately, C is neither type-safe nor memory-safe, and control-flow hijacking remains a prevalent threat. This paper presents Silhouette: a compiler-based defense that efficiently guarantees the integrity of return addresses, significantly reducing the attack surface for control-flow hijacking. Silhouette combines an incorruptible shadow stack for return addresses with checks on forward control flow and memory protection to ensure that all functions return to the correct dynamic caller. To protect its shadow stack, Silhouette uses store hardening, an efficient intra-address space isolation technique targeting various ARM architectures that leverages special store instructions found on ARM processors. We implemented Silhouette for the ARMv7-M architecture, but our techniques are applicable to other common embedded ARM architectures. Our evaluation shows that Silhouette incurs a geometric mean of 1.3% and 3.4% performance overhead on two benchmark suites. Furthermore, we prototyped Silhouette-Invert, an alternative implementation of Silhouette, which incurs just 0.3% and 1.9% performance overhead, at the cost of a minor hardware change.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- OPEC: operation-based security isolation for bare-metal embedded systemsXia Zhou, Jiaqi Li, Wenlong Zhang, Yajin Zhou 等EuroSys 2022 · 被引用 18 次
- SHERLOC: Secure and Holistic Control-Flow Violation Detection on Embedded SystemsXi Tan, Ziming ZhaoCCS 2023 · 被引用 13 次
- PANIC: PAN-assisted Intra-process Memory Isolation on ARMJiali Xu, Mengyao Xie, Chenggang Wu, Yinqian Zhang 等CCS 2023 · 被引用 11 次
- Opportunistic Data Flow Integrity for Real-time Cyber-physical Systems Using Worst Case Execution Time ReservationYujie Wang, Ao Li, Jinwen Wang, Sanjoy K. Baruah 等USENIX Security 2024 · 被引用 8 次
- HIVE: A Hardware-assisted Isolated Execution Environment for eBPF on AArch64Peihua Zhang, Chenggang Wu, Xiangyu Meng, Yinqian Zhang 等USENIX Security 2024 · 被引用 8 次
它引用的顶会 Paper6
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua 等S&P 2016 · 被引用 420 次
- SoK: Shining Light on Shadow StacksNathan Burow, Xinping Zhang, Mathias PayerS&P 2019 · 被引用 170 次
- Securing Real-Time Microcontroller Systems through Customized Memory View SwitchingChung Hwan Kim, Taegyu Kim, Hongjun Choi, Zhongshu Gu 等NDSS 2018 · 被引用 127 次
- Protecting Bare-Metal Embedded Systems with Privilege OverlaysAbraham A. Clements, Naif Saleh Almakhdhub, Khaled Saab, Prashast Srivastava 等S&P 2017 · 被引用 122 次
- ACES: Automatic Compartments for Embedded SystemsAbraham A. Clements, Naif Saleh Almakhdhub, Saurabh Bagchi, Mathias PayerUSENIX Security 2018 · 被引用 89 次
相关 Paper
- µRAI: Securing Embedded Systems with Return Address IntegrityNaif Saleh Almakhdhub, Abraham A. Clements, Saurabh Bagchi, Mathias PayerNDSS 2020
- XCFI: Comprehensive Control-Flow Integrity for Arm TrustZone-MYunju Gu, Jaeyeol Park, Donghyun KwonUSENIX Security 2026
- Block Oriented Programming: Automating Data-Only AttacksKyriakos K. Ispoglou, Bader AlBassam, Trent Jaeger, Mathias PayerCCS 2018 · 被引用 143 次
- SpecCFI: Mitigating Spectre Attacks using CFI Informed SpeculationEsmaeil Mohammadian Koruyeh, Shirin Haji Amin Shirazi, Khaled N. Khasawneh, Chengyu Song 等S&P 2020 · 被引用 74 次
- TZ-DATASHIELD: Automated Data Protection for Embedded Systems via Data-Flow-Based CompartmentalizationZelun Kong, Minkyung Park, Le Guan, Ning Zhang 等NDSS 2025
