ARTO: Efficient Execution Integrity Attestation for Real-Time Operation of Cyber-Physical Systems
Ruizhe Zhao, Cong Sun, Zongzhen Li, Tiantian Wang, Yunbo Wang
摘要
Real-time embedded systems are prevalent in cyber-physical applications such as drones and autonomous vehicles. Due to their high complexity, the environmental uncertainties, and the openness to remote control, these systems are vulnerable to control-flow hijacking and data-only attacks that compromise runtime integrity and reliability. Traditional control-flow integrity (CFI) and data-flow integrity (DFI) approaches impose excessive overhead, while the control-flow attestation (CFA) allows detection latency incompatible with real-time constraints. This paper presents ARTO, the first control-flow and data-flow protection approach that integrates the control-flow attestation to provide strong security with competitive runtime overhead. Through the prover-side path segmentation and hash-based validation result caching, ARTO provides partial context-sensitive protection at minimal runtime cost, offloading complete context-sensitive detection to the remote verifier. Furthermore, ARTO implements an equivalence-class-based data-flow protection that combines the address-based target check for memory reads with the value-based checks to protect critical variables, stronger than the SOTA operation integrity enforcement in validating the read source for critical variables. Extensive evaluations on robotic vehicle autopilots confirm ARTO's efficacy in mitigating both control-flow and data-only attacks while maintaining runtime overhead within real-time limits, outperforming SOTA CFA and operation-integrity enforcement methods in operation execution time.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper17
- C-FLAT: Control-Flow Attestation for Embedded Systems SoftwareTigist Abera, N. Asokan, Lucas Davi, Jan-Erik Ekberg 等CCS 2016 · 被引用 311 次
- Enforcing Unique Code Target Property for Control-Flow IntegrityHong Hu, Chenxiong Qian, Carter Yagemann, Simon Pak Ho Chung 等CCS 2018 · 被引用 142 次
- Securing Real-Time Microcontroller Systems through Customized Memory View SwitchingChung Hwan Kim, Taegyu Kim, Hongjun Choi, Zhongshu Gu 等NDSS 2018 · 被引用 127 次
- Efficient Protection of Path-Sensitive Control SecurityRen Ding, Chenxiong Qian, Chengyu Song, William Harris 等USENIX Security 2017 · 被引用 123 次
- Protecting Bare-Metal Embedded Systems with Privilege OverlaysAbraham A. Clements, Naif Saleh Almakhdhub, Khaled Saab, Prashast Srivastava 等S&P 2017 · 被引用 122 次
相关 Paper
- OAT: Attesting Operation Integrity of Embedded DevicesZhichuang Sun, Bo Feng, Long Lu, Somesh JhaS&P 2020 · 被引用 89 次
- Opportunistic Data Flow Integrity for Real-time Cyber-physical Systems Using Worst Case Execution Time ReservationYujie Wang, Ao Li, Jinwen Wang, Sanjoy K. Baruah 等USENIX Security 2024 · 被引用 8 次
- ACFA: Secure Runtime Auditing & Guaranteed Device Healing via Active Control Flow AttestationAdam Caulfield, Norrathep Rattanavipanon, Ivan De Oliveira NunesUSENIX Security 2023
- ARI: Attestation of Real-time Mission Execution IntegrityJinwen Wang, Yujie Wang, Ao Li, Yang Xiao 等USENIX Security 2023
- DIALED: Data Integrity Attestation for Low-end Embedded DevicesIvan De Oliveira Nunes, Sashidhar Jakkamsetti, Gene TsudikDAC 2021 · 被引用 27 次
