Apps Can Quickly Destroy Your Mobile's Flash: Why They Don't, and How to Keep It That Way

Apps Can Quickly Destroy Your Mobile's Flash: Why They Don't, and How to Keep It That Way
复制标题

DOI:
10.1145/3307334.3326108
复制
发表时间:
2019-06
期刊:
Proceedings of the 17th Annual International Conference on Mobile Systems, Applications, and Services
影响因子:
--
通讯作者:
Tao Zhang;A. Zuck;Donald E. Porter;Dan Tsafrir
Tao Zhang;A. Zuck;Donald E. Porter;Dan Tsafrir
中科院分区:
其他
文献类型:
--
作者:
Tao Zhang;A. Zuck;Donald E. Porter;Dan Tsafrir

文献摘要

被引文献

相似文献

尽管闪存单元会磨损,但一个典型的固态硬盘拥有足够多的单元以及足够复杂的固件,其使用寿命通常会超过其主机系统的预期寿命。即使在高强度使用的情况下,固态硬盘也能使用数年,并且在出现故障时可以更换。相比之下,在智能手机上,硬件条件更为有限,我们发现,在高强度使用的情况下,人们很容易且更迅速地磨损智能手机的闪存存储。因此,一个简单的、无特权的恶意应用程序可以在几周内使智能手机无法启动(“变砖”),而用户没有任何警示迹象。当考虑到智能手机用户普遍认为尝试新应用程序是安全的这一事实时,这个严峻的结果就更令人担忧了。为了解决这个问题,我们研究了大量安卓应用程序的输入/输出行为。我们发现存在大量的写入突发情况,然而我们检查的应用程序中没有一个能维持足够高的平均写入速率来损坏设备(在文献支持的合理使用假设下)。因此,我们提出了一种针对写入活动的速率限制算法,该算法(1)防止此类攻击,(2)适应“正常”的突发情况,(3)确保智能手机驱动器的使用寿命长于预先配置的下限(即其保修期)。在用户体验方面,我们的设计只要求在最坏的情况下,即一个应用程序持续发出不可持续且异常的写入操作时,用户决定是缩短手机寿命还是对有问题的应用程序进行速率限制。
Although flash cells wear out, a typical SSD has enough cells and sufficiently sophisticated firmware that its lifetime generally exceeds the expected lifetime of its host system. Even under heavy use, SSDs last for years and can be replaced upon failure. On a smartphone, in contrast, the hardware is more limited and we show that, under heavy use, one can easily, and more quickly, wear out smartphone flash storage. Consequently, a simple, unprivileged, malicious application can render a smartphone unbootable ("bricked") in a few weeks with no warning signs to the user. This bleak result becomes more worrisome when considering the fact that smartphone users generally believe it is safe to try out new applications. To combat this problem, we study the I/O behavior of a wide range of Android applications. We find that high-volume write bursts exist, yet none of the applications we checked sustains an average write rate that is high enough to damage the device (under reasonable usage assumptions backed by the literature). We therefore propose a rate-limiting algorithm for write activity that (1) prevents such attacks, (2) accommodates "normal" bursts, and (3) ensures that the smartphone drive lifetime is longer than a preconfigured lower bound (i.e., its warranty). In terms of user experience, our design only requires that, in the worst case of an app that issues continuous, unsustainable, and unusual writes, the user decides whether to shorten the phone's life or rate limit the problematic app.