OAT: Attesting Operation Integrity of Embedded Devices

OAT: Attesting Operation Integrity of Embedded Devices
复制标题

DOI:
10.1109/sp40000.2020.00042
复制
发表时间:
2018-02
期刊:
2020 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Zhichuang Sun;Bo Feng;Long Lu;S. Jha
Zhichuang Sun;Bo Feng;Long Lu;S. Jha
中科院分区:
其他
文献类型:
--
作者:
Zhichuang Sun;Bo Feng;Long Lu;S. Jha

文献摘要

被引文献

相似文献

由于物联网/CPS系统的广泛采用,嵌入式设备(物联网前端)变得越来越互联且关键任务,这反过来又吸引了高级攻击(例如控制流劫持和纯数据攻击)。不幸的是,物联网后端(例如远程控制器或云服务)在从物联网设备(远程部署的嵌入式设备)接收数据、服务请求或操作状态时无法检测是否发生了此类攻击。因此,目前物联网后端被迫盲目信任与之交互的物联网设备。为了填补这一空白,我们首先为嵌入式设备制定一个新的安全属性,称为“操作执行完整性”或 OEI。然后,我们设计并构建了一个系统 OAT,该系统支持对基于 ARM 的裸机嵌入式设备进行远程 OEI 认证。我们的 OEI 公式捕获了操作执行中涉及的控制流和关键数据的完整性。因此,满足 OEI 需要操作执行不受意外的控制和数据操纵,这是现有的证明方法无法检查的。我们的 OAT 设计在证明者的约束(嵌入式设备的有限计算能力和存储)和验证者的要求(完整的可验证性和取证协助)之间取得了平衡。 OAT 使用新的控制流测量方案,可实现轻量且节省空间的测量收集(与基于跟踪的方法相比,空间减少了 97%)。 OAT 通过抽象执行来执行远程控制流验证,速度快且确定性强。 OAT 还具有针对关键数据的轻量级完整性检查(比以前的工作减少了 74% 的仪器)。我们的安全分析表明,OAT 允许远程验证者或物联网后端检测影响物联网设备上操作执行的控制流劫持和纯数据攻击。在我们使用真实嵌入式程序的评估中,OAT 的运行时开销为 2.7%。
Due to the wide adoption of IoT/CPS systems, embedded devices (IoT frontends) become increasingly connected and mission-critical, which in turn has attracted advanced attacks (e.g., control-flow hijacks and data-only attacks). Unfortunately, IoT backends (e.g., remote controllers or in-cloud services) are unable to detect if such attacks have happened while receiving data, service requests, or operation status from IoT devices (remotely deployed embedded devices). As a result, currently, IoT backends are forced to blindly trust the IoT devices that they interact with.To fill this void, we first formulate a new security property for embedded devices, called "Operation Execution Integrity" or OEI. We then design and build a system, OAT, that enables remote OEI attestation for ARM-based bare-metal embedded devices. Our formulation of OEI captures the integrity of both control flow and critical data involved in an operation execution. Therefore, satisfying OEI entails that an operation execution is free of unexpected control and data manipulations, which existing attestation methods cannot check. Our design of OAT strikes a balance between prover’s constraints (embedded devices’ limited computing power and storage) and verifier’s requirements (complete verifiability and forensic assistance). OAT uses a new control-flow measurement scheme, which enables lightweight and space-efficient collection of measurements (97% space reduction from the trace-based approach). OAT performs the remote control-flow verification through abstract execution, which is fast and deterministic. OAT also features lightweight integrity checking for critical data (74% less instrumentation needed than previous work). Our security analysis shows that OAT allows remote verifiers or IoT backends to detect both controlflow hijacks and data-only attacks that affect the execution of operations on IoT devices. In our evaluation using real embedded programs, OAT incurs a runtime overhead of 2.7%.