Anatomy of Memory Corruption Attacks and Mitigations in Embedded Systems

Anatomy of Memory Corruption Attacks and Mitigations in Embedded Systems
复制标题

嵌入式系统中内存损坏攻击和缓解措施的剖析

DOI:
10.1109/les.2018.2829777
复制
发表时间:
2018
影响因子:
1.6
通讯作者:
Michail Maniatakos
Michail Maniatakos
中科院分区:
计算机科学4区
文献类型:
--
作者:
N. G. Tsoutsos;Michail Maniatakos

文献摘要

被引文献

相似文献

二十多年来,内存安全违规和控制流完整性攻击一直是计算机系统安全的一个突出威胁。与定期更新的常规系统相反,受应用程序约束的设备通常运行单片固件,在现场部署后,这些固件可能在设备的生命周期内不会更新。因此,防止内存损坏的需求变得更加突出。在这封信中,我们调查了嵌入式处理器背景下的内存安全性,并描述了可以破坏合法控制流的不同攻击,特别关注面向返回的编程。基于常见的攻击趋势,我们对典型的内存损坏攻击进行了剖析,并讨论了文献中报道的强大的缓解技术。
For more than two decades, memory safety violations and control-flow integrity attacks have been a prominent threat to the security of computer systems. Contrary to regular systems that are updated regularly, application-constrained devices typically run monolithic firmware that may not be updated in the lifetime of the device after being deployed in the field. Hence, the need for protections against memory corruption becomes even more prominent. In this letter, we survey memory safety in the context of embedded processors, and describe different attacks that can subvert the legitimate control flow, with a special focus on return oriented programming. Based on common attack trends, we formulate the anatomy of typical memory corruption attacks and discuss powerful mitigation techniques that have been reported in the literature.