Protecting Bare-Metal Embedded Systems with Privilege Overlays
Abraham A. Clements, Naif Saleh Almakhdhub, Khaled Saab, Prashast Srivastava, Jinkyu Koo, Saurabh Bagchi, Mathias Payer
摘要
Embedded systems are ubiquitous in every aspect of modern life. As the Internet of Thing expands, our dependence on these systems increases. Many of these interconnected systems are and will be low cost bare-metal systems, executing without an operating system. Bare-metal systems rarely employ any security protection mechanisms and their development assumptions (unrestricted access to all memory and instructions), and constraints (runtime, energy, and memory) makes applying protections challenging. To address these challenges we present EPOXY, an LLVMbased embedded compiler. We apply a novel technique, called privilege overlaying, wherein operations requiring privileged execution are identified and only these operations execute in privileged mode. This provides the foundation on which codeintegrity, adapted control-flow hijacking defenses, and protections for sensitive IO are applied. We also design fine-grained randomization schemes, that work within the constraints of baremetal systems to provide further protection against control-flow and data corruption attacks. These defenses prevent code injection attacks and ROP attacks from scaling across large sets of devices. We evaluate the performance of our combined defense mechanisms for a suite of 75 benchmarks and 3 real-world IoT applications. Our results for the application case studies show that EPOXY has, on average, a 1.8% increase in execution time and a 0.5% increase in energy usage.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper33
- Detecting Attacks Against Robotic Vehicles: A Control Invariant ApproachHongjun Choi, Wen-Chuan Lee, Yousra Aafer, Fan Fei 等CCS 2018 · 被引用 201 次
- Securing Real-Time Microcontroller Systems through Customized Memory View SwitchingChung Hwan Kim, Taegyu Kim, Hongjun Choi, Zhongshu Gu 等NDSS 2018 · 被引用 127 次
- OAT: Attesting Operation Integrity of Embedded DevicesZhichuang Sun, Bo Feng, Long Lu, Somesh JhaS&P 2020 · 被引用 89 次
- ACES: Automatic Compartments for Embedded SystemsAbraham A. Clements, Naif Saleh Almakhdhub, Saurabh Bagchi, Mathias PayerUSENIX Security 2018 · 被引用 89 次
- Dominance as a New Trusted Computing Primitive for the Internet of ThingsMeng Xu, Manuel Huber, Zhichuang Sun, Paul England 等S&P 2019 · 被引用 61 次
它引用的顶会 Paper3
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua 等S&P 2016 · 被引用 420 次
- C-FLAT: Control-Flow Attestation for Embedded Systems SoftwareTigist Abera, N. Asokan, Lucas Davi, Jan-Erik Ekberg 等CCS 2016 · 被引用 311 次
- Leakage-Resilient Layout Randomization for Mobile DevicesKjell Braden, Lucas Davi, Christopher Liebchen, Ahmad-Reza Sadeghi 等NDSS 2016 · 被引用 90 次
相关 Paper
- µRAI: Securing Embedded Systems with Return Address IntegrityNaif Saleh Almakhdhub, Abraham A. Clements, Saurabh Bagchi, Mathias PayerNDSS 2020
- OPEC: operation-based security isolation for bare-metal embedded systemsXia Zhou, Jiaqi Li, Wenlong Zhang, Yajin Zhou 等EuroSys 2022 · 被引用 18 次
- Silhouette: Efficient Protected Shadow Stacks for Embedded SystemsJie Zhou, Yufei Du, Zhuojia Shen, Lele Ma 等USENIX Security 2020
- Enforcing Kernel Security Invariants with Data Flow IntegrityChengyu Song, Byoungyoung Lee, Kangjie Lu, William Harris 等NDSS 2016 · 被引用 141 次
- Intellectual Property Exposure: Subverting and Securing Intellectual Property Encapsulation in Texas Instruments MicrocontrollersMarton Bognar, Cas Magnus, Frank Piessens, Jo Van BulckUSENIX Security 2024 · 被引用 4 次
