On the Pitfalls and Vulnerabilities of Schedule Randomization Against Schedule-Based Attacks

On the Pitfalls and Vulnerabilities of Schedule Randomization Against Schedule-Based Attacks
复制标题

DOI:
10.1109/rtas.2019.00017
复制
发表时间:
2019-04
期刊:
2019 IEEE Real-Time and Embedded Technology and Applications Symposium (RTAS)
影响因子:
--
通讯作者:
M. Nasri;Thidapat Chantem;Gedare Bloom;Ryan M. Gerdes
M. Nasri;Thidapat Chantem;Gedare Bloom;Ryan M. Gerdes
中科院分区:
其他
文献类型:
--
作者:
M. Nasri;Thidapat Chantem;Gedare Bloom;Ryan M. Gerdes

文献摘要

被引文献

相似文献

调度随机化是最近引入的针对基于调度的攻击的安全防御之一,即,成功与否取决于攻击者执行窗口和系统内受害者任务之间的特定顺序的攻击。它福尔斯信息隐藏的范畴(与基于确定性隔离的防御相反),旨在降低攻击者推断未来时间表的能力。本文旨在研究实时系统中基于调度随机化的防御的局限性和脆弱性。我们首先提供基于时间表的攻击的定义、分类和例子,然后讨论在实时系统中采用时间表随机化的挑战。此外,我们提供了一个初步的安全测试,以确定是否一定的攻击者和受害者的任务之间的时序关系将永远不会发生在系统中的固定优先级调度算法调度。最后,我们比较了固定优先级调度对调度随机化技术的成功率的各种基于调度的攻击合成和现实世界的应用程序。我们的结果表明,在许多情况下,调度随机化要么没有安全益处,要么甚至可以增加攻击者的成功率,具体取决于攻击者和受害者任务之间的优先级关系。
Schedule randomization is one of the recently introduced security defenses against schedule-based attacks, i.e., attacks whose success depends on a particular ordering between the execution window of an attacker and a victim task within the system. It falls into the category of information hiding (as opposed to deterministic isolation-based defenses) and is designed to reduce the attacker's ability to infer the future schedule. This paper aims to investigate the limitations and vulnerabilities of schedule randomization-based defenses in real-time systems. We first provide definitions, categorization, and examples of schedule-based attacks, and then discuss the challenges of employing schedule randomization in real-time systems. Further, we provide a preliminary security test to determine whether a certain timing relation between the attacker and victim tasks will never happen in systems scheduled by a fixed-priority scheduling algorithm. Finally, we compare fixed-priority scheduling against schedule-randomization techniques in terms of the success rate of various schedule-based attacks for both synthetic and real-world applications. Our results show that, in many cases, schedule randomization either has no security benefits or can even increase the success rate of the attacker depending on the priority relation between the attacker and victim tasks.