AVGuardian: Detecting and Mitigating Publish-Subscribe Overprivilege for Autonomous Vehicle Systems

AVGuardian: Detecting and Mitigating Publish-Subscribe Overprivilege for Autonomous Vehicle Systems
复制标题

DOI:
10.1109/eurosp48549.2020.00035
复制
发表时间:
2020-09
期刊:
2020 IEEE European Symposium on Security and Privacy (EuroS&P)
影响因子:
--
通讯作者:
David Ke Hong;John Kloosterman;Yuqi Jin;Yulong Cao;Qi Alfred Chen;S. Mahlke;Z. Morley Mao
David Ke Hong;John Kloosterman;Yuqi Jin;Yulong Cao;Qi Alfred Chen;S. Mahlke;Z. Morley Mao
中科院分区:
其他
文献类型:
--
作者:
David Ke Hong;John Kloosterman;Yuqi Jin;Yulong Cao;Qi Alfred Chen;S. Mahlke;Z. Morley Mao

文献摘要

被引文献

相似文献

自动驾驶汽车(AV)软件系统正在涌现,以实现快速发展的自动驾驶功能。由于此类系统负责安全关键决策,因此有必要在面临网络攻击时确保它们的安全。通过对具有代表性的反病毒软件系统百度Apollo和Autware的实证研究,我们发现了反病毒系统广泛采用的发布-订阅通信模型中普遍存在的权限过大问题:由于发布-订阅通信的粗粒度消息设计,一些消息字段被过度授予发布/订阅权限。为了符合最小特权原则,减少此类问题造成的攻击面,我们认为发布/订阅权限应该在消息字段而不是消息的粒度上定义和实施。为了系统地解决这样的发布-订阅过度权限问题,我们提出了一个AVGuardian系统,它包括(1)一个静态分析工具,它检测反病毒软件中的过度特权实例,并在消息字段粒度上生成相应的访问控制策略;(2)一个低开销、模块透明的运行时发布/订阅权限策略执行机制,以执行在线策略违规检测和预防。使用我们的检测工具,我们能够自动检测到百度Apollo中总共581个过度特权实例。为了证明严重性,我们进一步构建了几个可能导致AV所有者车辆碰撞和身份盗窃的具体攻击,这些攻击已经报告给百度Apollo,并被确认为有效。在防御方面,我们对策略执行机制进行了原型和评估,发现它具有很低的开销,不影响原有的反病毒决策逻辑,并且对消息重放攻击具有弹性。
Autonomous vehicle (AV) software systems are emerging to enable rapidly developed self-driving functionalities. Since such systems are responsible for safety-critical decisions, it is necessary to secure them in face of cyber attacks. Through an empirical study of representative AV software systems Baidu Apollo and Autoware, we discover a common over privilege problem with the publish-subscribe communication model widely adopted by AV systems: due to the coarse-grained message design for the publish-subscribe communication, some message fields are over-granted with publish/subscribe permissions. To comply with the least-privilege principle and reduce the attack surface resulting from such problem, we argue that the publish/subscribe permissions should be defined and enforced at the granularity of message fields instead of messages. To systematically address such publish-subscribe over-privilege problems, we present AVGuardian, a system that includes (1) a static analysis tool that detects overprivilege instances in AV software and generates the corresponding access control policies at the message field granularity, and (2) a low-overhead, module-transparent, runtime pub-lish/subscribe permission policy enforcement mechanism to perform online policy violation detection and prevention. Using our detection tool, we are able to automatically detect 581 overprivilege instances in total in Baidu Apollo. To demonstrate the severity, we further constructed several concrete exploits that can lead to vehicle collision and identity theft for AV owners, which have been reported to Baidu Apollo and confirmed as valid. For defense, we prototype and evaluate the policy enforcement mechanism, and find that it has very low overhead, does not affect original AV decision logic, and also is resilient to message replay attacks.