Low-end embedded devices are increasingly used in various smart applications and spaces. They are implemented under strict cost and energy budgets, using microcontroller units (MCUs) that lack security features available in general-purpose processors. In this context, Remote Attestation (RA) was proposed as an inexpensive security service to enable a verifier (Vrf) to remotely detect illegal modifications to a software binary installed on a low-end prover MCU (Prv). Since attacks that hijack the software's control flow can evade RA, Control Flow Attestation (CFA) augments RA with information about the exact order in which instructions in the binary are executed, enabling detection of control flow attacks. We observe that current CFA architectures can not guarantee that Vrf ever receives control flow reports in case of attacks. In turn, while they support exploit detection, they provide no means to pinpoint the exploit origin. Furthermore, existing CFA requires either binary instrumentation, incurring significant runtime overhead and code size increase, or relatively expensive hardware support, such as hash engines. In addition, current techniques are neither continuous (only meant to attest self-contained operations) nor active (offer no secure means to remotely remediate detected compromises). To jointly address these challenges, we propose ACFA: a hybrid (hardware/software) architecture for Active CFA. ACFA enables continuous monitoring of all control flow transfers in the MCU and does not require binary instrumentation. It also leverages the recently proposed concept of Active Roots-of-Trust to enable secure auditing of vulnerability sources and guaranteed remediation when a compromise is detected. We provide an open-source reference implementation of ACFA on top of a commodity low-end MCU (TI MSP430) and evaluate it to demonstrate its security and cost-effectiveness.


翻译:低端嵌入式设备越来越多地应用于各类智能应用场景。受限于严格的成本与能耗预算,这些设备采用缺乏通用处理器安全特性的微控制器单元(MCU)实现。在此背景下,远程证明(RA)被提出作为一种低成本安全服务,使验证者(Vrf)能够远程检测安装在低端证明者MCU(Prv)上的软件二进制是否遭受非法篡改。由于劫持软件控制流的攻击可绕过RA检测,控制流证明(CFA)通过补充二进制指令执行顺序的精确信息来增强RA能力,从而实现对控制流攻击的检测。我们发现当前CFA架构无法保证在攻击发生时Vrf能够接收到控制流报告。此外,虽然这类架构支持漏洞检测,但无法定位漏洞来源。现有CFA要么需要二进制插桩(导致显著运行时开销和代码体积增加),要么依赖相对昂贵的硬件支持(如哈希引擎)。更严重的是,当前技术既不具备连续性(仅用于证明自包含操作),也缺乏主动性(无法通过安全手段远程修复已检测到的入侵)。为联合应对这些挑战,我们提出ACFA:一种用于主动CFA的混合(硬件/软件)架构。ACFA支持对MCU中所有控制流转移的持续监控,且无需二进制插桩。该架构利用最新提出的主动可信根概念,实现漏洞源的安全审计,并在检测到入侵时提供可靠修复。我们基于商用低端MCU(TI MSP430)提供了ACFA的开源参考实现,并通过评估验证了其安全性与成本效益。

0
下载
关闭预览

相关内容

《基于联邦学习的全球协同威胁检测》
专知会员服务
32+阅读 · 2023年3月13日
巴西空军《用于评估军事作战场景的仿真环境》最新论文
专知会员服务
134+阅读 · 2022年9月23日
多智能体顶级会议AAMAS2022最佳论文
专知会员服务
64+阅读 · 2022年5月15日
【2020新书】Web应用安全,331页pdf
专知会员服务
25+阅读 · 2020年10月24日
Kafka 3.3使用KRaft共识协议替代ZooKeeper
InfoQ
0+阅读 · 2022年11月1日
Docker 发布 WebAssembly 支持工具预览版
InfoQ
0+阅读 · 2022年10月26日
升级 Android 认证: 远程配置
谷歌开发者
1+阅读 · 2022年5月26日
已删除
将门创投
11+阅读 · 2019年8月13日
A Technical Overview of AI & ML in 2018 & Trends for 2019
待字闺中
18+阅读 · 2018年12月24日
国家自然科学基金
0+阅读 · 2016年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
国家自然科学基金
2+阅读 · 2013年12月31日
国家自然科学基金
1+阅读 · 2012年12月31日
国家自然科学基金
0+阅读 · 2012年12月31日
国家自然科学基金
0+阅读 · 2012年12月31日
国家自然科学基金
0+阅读 · 2012年12月31日
国家自然科学基金
0+阅读 · 2011年12月31日
国家自然科学基金
0+阅读 · 2009年12月31日
国家自然科学基金
0+阅读 · 2009年12月31日
Arxiv
0+阅读 · 2023年5月18日
Arxiv
0+阅读 · 2023年5月16日
VIP会员
最新内容
一种考虑资源机动性的武器目标分配混合算法
专知会员服务
4+阅读 · 8月8日
《多域冲突比较支持模型》60页
专知会员服务
10+阅读 · 8月7日
面向2027年及未来的海军情报改革
专知会员服务
6+阅读 · 8月5日
相关VIP内容
相关基金
国家自然科学基金
0+阅读 · 2016年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
国家自然科学基金
2+阅读 · 2013年12月31日
国家自然科学基金
1+阅读 · 2012年12月31日
国家自然科学基金
0+阅读 · 2012年12月31日
国家自然科学基金
0+阅读 · 2012年12月31日
国家自然科学基金
0+阅读 · 2012年12月31日
国家自然科学基金
0+阅读 · 2011年12月31日
国家自然科学基金
0+阅读 · 2009年12月31日
国家自然科学基金
0+阅读 · 2009年12月31日
Top
微信扫码咨询专知VIP会员