Manipulative Interference Attacks
Samuel Mergendahl, Stephen Fickas, Boyana Norris, Richard Skowyra
摘要
A µ-kernel is an operating system (OS) paradigm that facilitates a strong cybersecurity posture for embedded systems. Unlike a monolithic OS such as Linux, a µ-kernel reduces overall system privilege by deploying most OS functionality within isolated, userspace protection domains. Moreover, a µ-kernel ensures confidentiality and integrity between protection domains (i.e., spatial isolation), and offers timing predictability for real-time tasks in mixed-criticality systems (i.e., temporal isolation). One popular µ-kernel is seL4 which offers extensive formal guarantees of implementation correctness and flexible temporal budgeting mechanisms. However, we show that an untrusted protection domain on a µ-kernel can abuse service requests to other protection domains in order to corrode system availability. We generalize this denial-of-service (DoS) attack strategy as Manipulative Interference Attacks (MIAs) and introduce techniques to efficiently identify instances of MIAs within a configured system. Specifically, we propose a novel hybrid approach that first leverages static analysis to identify software components with influenceable execution times, and second, uses an automatically generated model-based analysis to determine which compromised protection domains can manipulate the influenceable components and trigger MIAs. We investigate the risk of MIAs in several representative system examples including the seL4 Microkit, as well as a case study of seL4 software artifacts from the DARPA Cyber Assured Systems Engineering (CASE) program. In particular, we demonstrate that our analysis is efficient enough to discover practical instances of MIAs in real-world systems. CCS Concepts • Computer systems organization → Embedded software; Real-time system specification; • Software and its engineering → Model checking; Automated static analysis; State systems; • Security and privacy → Denial-of-service attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper20
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua 等S&P 2016 · 被引用 420 次
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler 等USENIX Security 2019 · 被引用 247 次
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na 等S&P 2019 · 被引用 196 次
- SoK: Shining Light on Shadow StacksNathan Burow, Xinping Zhang, Mathias PayerS&P 2019 · 被引用 170 次
相关 Paper
- IsolatOS: Detecting Double Fetch Bugs in COTS RTOS by Re-enabling Kernel IsolationYingjie Cao, Xiaogang Zhu, Dean Sullivan, Haowei Yang 等NDSS 2026 · 被引用 1 次
- Harmonizing Performance and Isolation in Microkernels with Efficient Intra-kernel Isolation and CommunicationJinyu Gu, Xinyue Wu, Wentai Li, Nian Liu 等USENIX ATC 2020 · 被引用 51 次
- Virtual timeline: a formal abstraction for verifying preemptive schedulers with temporal isolationMengqi Liu, Lionel Rieg, Zhong Shao, Ronghui Gu 等POPL 2020 · 被引用 17 次
- Fractal: An Operating System Designed for Microarchitecture Reverse EngineeringJoseph Ravichandran, Mengjia YanS&P 2026
- Compositional virtual timelines: verifying dynamic-priority partitions with algorithmic temporal isolationMengqi Liu, Zhong Shao, Hao Chen, Man-Ki Yoon 等OOPSLA 2022 · 被引用 2 次
