SoK: A Security Architect's View of Printed Circuit Board Attacks
Jacob Harrison, Nathan Jessurun, Mark Tehranipoor
摘要
Many recent papers have proposed novel electrical measurements or physical inspection technologies for defending printed circuit boards (PCBs) and printed circuit board assemblies (PCBAs) against tampering. As motivation, these papers frequently cite Bloomberg News'"The Big Hack", video game modchips, and"interdiction attacks"on IT equipment. We find this trend concerning for two reasons. First, implementation errors and security architecture are rarely discussed in recent PCBA security research, even though they were the root causes of these commonly-cited attacks and most other attacks that have occurred or been proposed by researchers. This suggests that the attacks may be poorly understood. Second, if we assume that novel countermeasures and validation methodologies are tailored to these oft-cited attacks, then significant recent work has focused on attacks that can already be mitigated instead of on open problems. We write this SoK to address these concerns. We explain which tampering threats can be mitigated by PCBA security architecture. Then, we enumerate assumptions that security architecture depends on. We compare and contrast assurances achieved by security architecture vs. by recently-proposed electrical or inspection-based tamper detection. Finally, we review over fifty PCBA attacks to show how most can be prevented by proper architecture and careful implementation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- FirmUSB: Vetting USB Device Firmware using Domain Informed Symbolic ExecutionGrant Hernandez, Farhaan Fowze, Dave (Jing) Tian, Tuba Yavuz 等CCS 2017 · 被引用 98 次
- Hard Drive of Hearing: Disks that Eavesdrop with a Synthesized MicrophoneAndrew Kwong, Wenyuan Xu, Kevin FuS&P 2019 · 被引用 63 次
- A Bus Authentication and Anti-Probing Architecture Extending Hardware Trusted Computing Base Off CPU Chips and BeyondZhenyu Xu, Thomas Mauldin, Zheyi Yao, Shuyi Pei 等ISCA 2020 · 被引用 23 次
- VIPR-PCB: a machine learning based golden-free PCB assurance frameworkAritra Bhattacharyay, Prabuddha Chakraborty, Jonathan Cruz, Swarup BhuniaDAC 2022 · 被引用 2 次
- PCSPOOF: Compromising the Safety of Time-Triggered EthernetAndrew D. Loveless, Linh Thi Xuan Phan, Ronald G. Dreslinski, Baris KasikciS&P 2023
相关 Paper
- An In-Depth Analysis of Disassembly on Full-Scale x86/x64 BinariesDennis Andriesse, Xi Chen, Victor van der Veen, Asia Slowinska 等USENIX Security 2016 · 被引用 162 次
- SoK: The Challenges, Pitfalls, and Perils of Using Hardware Performance Counters for SecuritySanjeev Das, Jan Werner, Manos Antonakakis, Michalis Polychronakis 等S&P 2019 · 被引用 163 次
- Volttack: Control IoT Devices by Manipulating Power Supply VoltageKai Wang, Shilin Xiao, Xiaoyu Ji, Chen Yan 等S&P 2023
- A Resource Binding Approach to Logic ObfuscationMichael Zuzak, Yuntao Liu, Ankur SrivastavaDAC 2021 · 被引用 15 次
- PowerRadio: Manipulate Sensor Measurement via Power GND RadiationYan Jiang, Xiaoyu Ji, Yancheng Jiang, Kai Wang 等NDSS 2025
