Integrated data space randomization and control reconfiguration for securing cyber-physical systems

Integrated data space randomization and control reconfiguration for securing cyber-physical systems
复制标题

用于保护网络物理系统的集成数据空间随机化和控制重新配置

DOI:
10.1145/3314058.3314064
复制
发表时间:
2019
期刊:
Proceedings of the 6th Annual Symposium on Hot Topics in the Science of Security (HotSoS '19
影响因子:
--
通讯作者:
Koutsoukos, Xenofon
Koutsoukos, Xenofon
中科院分区:
--
文献类型:
--
作者:
Potteiger, Bradley;Zhang, Zhenkai;Koutsoukos, Xenofon

文献摘要

参考文献

被引文献

相似文献

非控制数据攻击已成为广泛流行的绕过身份验证机制的网站,服务器和个人计算机。此外,在网络物理系统(CPS)的背景下,攻击不仅可以针对身份验证,还可以针对安全。由于网络组件与物理动态之间的紧密耦合性质,任何未经授权的对安全关键变量的更改都可能导致损害甚至灾难性后果。移动目标防御(MTD)技术,如数据空间随机化(DSR),可以有效地防止各种类型的内存损坏攻击,包括非控制数据攻击。然而,就CPS而言,在MTD挫败攻击后确保及时的网络物理交互也是至关重要的。本文通过开发一种DSR方法在运行时随机化二进制文件,创建一种基于变量冗余的检测算法来识别变量完整性违规,以及集成一种控制重构架构来维护安全可靠的运行,解决了在面对非控制数据攻击时维护CPS系统稳定性和安全属性的问题。我们的安全框架通过自动驾驶汽车案例研究进行了演示。
Non-control data attacks have become widely popular for circumventing authentication mechanisms in websites, servers, and personal computers. Moreover, in the context of Cyber-Physical Systems (CPS) attacks can be executed against not only authentication but also safety. With the tightly coupled nature between the cyber components and physical dynamics, any unauthorized change to safety-critical variables may cause damage or even catastrophic consequences. Moving target defense (MTD) techniques such as data space randomization (DSR) can be effective for protecting against various types of memory corruption attacks including non-control data attacks. However, in terms of CPS it is also critical to ensure the timely Cyber-Physical interactions after attacks thwarted by MTD. This paper addresses the problem of maintaining system stability and security properties of a CPS in the face of non-control data attacks by developing a DSR approach for randomizing binaries at runtime, creating a variable redundancy based detection algorithm for identifying variable integrity violations, and integrating a control reconfiguration architecture for maintaining safe and reliable operation. Our security framework is demonstrated utilizing an autonomous vehicle case study.
DOI: 10.1145/3055004.3055010
发表时间: 2017-04
期刊: 2017 ACM/IEEE 8th International Conference on Cyber-Physical Systems (ICCPS)
影响因子: --
作者:
Man-Ki Yoon;Bo Liu;N. Hovakimyan;L. Sha
通讯作者: Man-Ki Yoon;Bo Liu;N. Hovakimyan;L. Sha
DOI: 10.1007/978-3-540-70542-0_1
发表时间: 2008-07
影响因子: --
作者:
S. Bhatkar;R. Sekar
通讯作者: S. Bhatkar;R. Sekar
案例研究:使用线性矩阵不等式 (LMI) 开发用于 F-16 飞机自动着陆的基线控制器
DOI: --
发表时间: 2000
期刊:
影响因子: --
作者:
D. Seto;E. Ferreira;T. Marz
通讯作者: T. Marz
用于保护网络物理系统的集成指令集随机化和控制重新配置
DOI: 10.1145/3190619.3190636
发表时间: 2018
期刊: HoTSoS '18 Proceedings of the 5th Annual Symposium and Bootcamp on Hot Topics in the Science of Security
影响因子: --
作者:
Potteiger, Bradley;Zhang, Zhenkai;Koutsoukos, Xenofon
通讯作者: Koutsoukos, Xenofon
曼波
DOI: --
发表时间: 2016
期刊: ACM Transactions on Architecture and Code Optimization (TACO)
影响因子: --
作者:
Cosmin Gorgovan;Amanieu D'Antras;M. Luján
通讯作者: M. Luján