DO-RA: Data-oriented runtime attestation for IoT devices

DO-RA: Data-oriented runtime attestation for IoT devices
复制标题

DOI:
10.1016/j.cose.2020.101945
复制
发表时间:
2020-06
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
Boyu Kuang;Anmin Fu;Lu Zhou;W. Susilo;Yuqing Zhang
Boyu Kuang;Anmin Fu;Lu Zhou;W. Susilo;Yuqing Zhang
中科院分区:
其他
文献类型:
--
作者:
Boyu Kuang;Anmin Fu;Lu Zhou;W. Susilo;Yuqing Zhang

文献摘要

被引文献

相似文献

远程证明是确认物联网(IoT)设备安全状态的绝佳方法。它允许实体(验证者)验证潜在受损平台(证明者)的完整性。当前的大多数证明方案都是静态的,仅验证设备的软件完整性。近年来,一些基于程序控制流图(CFG)的运行时证明方案被提出来收集运行时信息。然而,构造CFG的算法只关注程序控制流的合理性,而忽略了攻击者通过修改关键数据来破坏设备控制流的可能性。运行时利用技术的一些缓解措施考虑了控制流的唯一代码目标(UCT)属性,但其算法找出约束数据的能力存在局限性。本文提出了一种面向数据的控制流图(DO-CFG),它可以为每个控制流转移匹配一个合法目标,从而保证程序控制流的合理性和唯一性。在此基础上,提出了一种基于DO-CFG的面向数据的认证方案(DO-RA)。它收集了一些关键的非控制数据,以提高证明方案的检测能力,从而进一步保证了控制流的唯一性。我们还提出了一个详细的概念验证实现,并分析了我们基于Raspberry Pi的协议。我们模拟了几个真实的应用程序来评估的安全性和性能的DO-RA,这表明我们的计划提供了一个更全面的检测能力在一个可接受的开销。
Remote attestation is an excellent approach to confirm the security states of Internet of Things (IoT) devices. It allows an entity (verifier) to validate the integrity of a potentially compromised platform (prover). Most of the current attestation schemes are static, which verify only the software integrity of devices. Recently, some runtime attestation schemes based on the Control Flow Graph (CFG) of the program have been proposed to collect the runtime information. However, the algorithm for constructing CFG only focuses on the rationality of the programs’ control flow, and ignores the possibility that attackers could compromise the control flow of the device by modifying key data. Some mitigation of runtime exploitation technologies take into account the Unique Code Target (UCT) property of control flow, but there are limitations to their algorithms abilities to find out the constraining data. In this paper, we present a Data-Oriented Control Flow Graph (DO-CFG) that can match a single legitimate target for each control-flow transfer, which guarantees both the rationality and the full uniqueness of programs’ control flow. Furthermore, we propose a Data-Oriented Runtime Attestation (DO-RA) scheme based on DO-CFG. It collects some critical non-control data to enhance the detection ability of the attestation scheme, which further ensures the uniqueness of the control flow. We also present a detailed proof-of-concept implementation and analyze our protocol based on Raspberry Pi. We simulate several real applications to evaluate the security and performance of DO-RA, which demonstrates that our scheme provides a more comprehensive detection capability within an acceptable overhead.