Holistic Control-Flow Protection on Real-Time Embedded Systems with Kage
Yufei Du, Zhuojia Shen, Komail Dharsee, Jie Zhou, Robert J. Walls, John Criswell
摘要
This paper presents Kage: a system that protects the control data of both application and kernel code on microcontrollerbased embedded systems. Kage consists of a Kage-compliant embedded OS that stores all control data in separate memory regions from untrusted data, a compiler that transforms code to protect these memory regions efficiently and to add forwardedge control-flow integrity checks, and a secure API that allows safe updates to the protected data. We implemented Kage as an extension to FreeRTOS, an embedded real-time operating system. We evaluated Kage's performance using the CoreMark benchmark. Kage incurred a 5.2% average runtime overhead and 49.8% code size overhead. Furthermore, the code size overhead was only 14.2% when compared to baseline FreeRTOS with the MPU enabled. We also evaluated Kage's security guarantees by measuring and analyzing reachable code-reuse gadgets. Compared to FreeRTOS, Kage reduces the number of reachable gadgets from 2,276 to 27, and the remaining 27 gadgets cannot be stitched together to launch a practical attack. * Part of the work was done when the author was a MS student at University of Rochester.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- SHERLOC: Secure and Holistic Control-Flow Violation Detection on Embedded SystemsXi Tan, Ziming ZhaoCCS 2023 · 被引用 13 次
- Opportunistic Data Flow Integrity for Real-time Cyber-physical Systems Using Worst Case Execution Time ReservationYujie Wang, Ao Li, Jinwen Wang, Sanjoy K. Baruah 等USENIX Security 2024 · 被引用 8 次
- μCFI: Formal Verification of Microarchitectural Control-flow IntegrityKatharina Ceesay-Seitz, Flavien Solt, Kaveh RazaviCCS 2024 · 被引用 3 次
- 'We just did not have that on the embedded system': Insights and Challenges for Securing Microcontroller Systems from the Embedded CTF CompetitionsZheyuan Ma, Gaoxiang Liu, Alex Eastman, Kai Kaufman 等CCS 2025
- The Cost of Performance: Breaking ThreadX with Kernel Object Masquerading AttacksXinhui Shao, Zhen Ling, Yue Zhang, Huaiyu Yan 等USENIX Security 2025
它引用的顶会 Paper2
- Protecting Bare-Metal Embedded Systems with Privilege OverlaysAbraham A. Clements, Naif Saleh Almakhdhub, Khaled Saab, Prashast Srivastava 等S&P 2017 · 被引用 122 次
- ACES: Automatic Compartments for Embedded SystemsAbraham A. Clements, Naif Saleh Almakhdhub, Saurabh Bagchi, Mathias PayerUSENIX Security 2018 · 被引用 89 次
相关 Paper
- Low-Cost Privilege Separation with Compile Time Compartmentalization for Embedded SystemsArslan Khan, Dongyan Xu, Dave Jing TianS&P 2023
- EC: Embedded Systems Compartmentalization via Intra-Kernel IsolationArslan Khan, Dongyan Xu, Dave Jing TianS&P 2023
- Page-Oriented Programming: Subverting Control-Flow Integrity of Commodity Operating System Kernels with Non-Writable Code PagesSeunghun Han, Seong-Joong Kim, Wook Shin, Byung Joon Kim 等USENIX Security 2024 · 被引用 9 次
- µRAI: Securing Embedded Systems with Return Address IntegrityNaif Saleh Almakhdhub, Abraham A. Clements, Saurabh Bagchi, Mathias PayerNDSS 2020
- Kintsugi: Secure Hotpatching for Code-Shadowing Real-Time Embedded SystemsPhilipp Mackensen, Christian Niesler, Roberto Blanco, Lucas Davi 等USENIX Security 2025
