PCSPOOF: Compromising the Safety of Time-Triggered Ethernet

PCSPOOF: Compromising the Safety of Time-Triggered Ethernet
复制标题

DOI:
10.1109/sp46215.2023.10179318
复制
发表时间:
2023-05
期刊:
2023 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
A. Loveless;L. T. Phan;R. Dreslinski;Baris Kasikci
A. Loveless;L. T. Phan;R. Dreslinski;Baris Kasikci
中科院分区:
其他
文献类型:
--
作者:
A. Loveless;L. T. Phan;R. Dreslinski;Baris Kasikci

文献摘要

被引文献

相似文献

设计人员越来越多地在嵌入式系统中使用混合临界网络,以减小尺寸、重量、功耗和成本。这些技术中最成功的可能是时间触发以太网(TTE),它允许关键时间触发(TT)流量和非关键尽力而为(BE)流量共享相同的交换机和布线。TTE的一个关键方面是系统的TT部分与BE部分是隔离的,因此BE设备没有办法中断TTE设备的操作。这种隔离允许设计人员:(1)使用不可信但成本低的BE硬件,(2)降低BE安全要求,以及(3)在安全审查和认证过程中忽略BE设备。我们提出了PCSPOOF,这是第一个打破TTE隔离保证的攻击。PCSPOOF基于两个关键观察结果。首先,BE设备有可能推断出有关网络TT部分的私有信息,这些信息可用于制作恶意同步消息。其次,通过以太网电缆向TTE交换机注入电气噪声,BE设备可以欺骗交换机向其他TTE设备发送这些恶意同步消息。我们的评估表明,成功的攻击可能在几秒钟内发生,每次成功的攻击都可能导致TTE设备失去同步长达一秒钟,并丢失数十条TT消息——这两种情况都可能导致飞机或汽车等关键系统的故障。我们还表明,在模拟的航天任务中,PCSPOOF会导致不受控制的机动,从而威胁安全和任务的成功。我们向使用TTE的航空航天公司披露了PCSPOOF,一些公司正在实施本文提出的缓解措施。
Designers are increasingly using mixed-criticality networks in embedded systems to reduce size, weight, power, and cost. Perhaps the most successful of these technologies is Time-Triggered Ethernet (TTE), which lets critical time-triggered (TT) traffic and non-critical best-effort (BE) traffic share the same switches and cabling. A key aspect of TTE is that the TT part of the system is isolated from the BE part, and thus BE devices have no way to disrupt the operation of the TTE devices. This isolation allows designers to: (1) use untrusted, but low cost, BE hardware, (2) lower BE security requirements, and (3) ignore BE devices during safety reviews and certification procedures.We present PCSPOOF, the first attack to break TTE’s isolation guarantees. PCSPOOF is based on two key observations. First, it is possible for a BE device to infer private information about the TT part of the network that can be used to craft malicious synchronization messages. Second, by injecting electrical noise into a TTE switch over an Ethernet cable, a BE device can trick the switch into sending these malicious synchronization messages to other TTE devices. Our evaluation shows that successful attacks are possible in seconds, and that each successful attack can cause TTE devices to lose synchronization for up to a second and drop tens of TT messages — both of which can result in the failure of critical systems like aircraft or automobiles. We also show that, in a simulated spaceflight mission, PCSPOOF causes uncontrolled maneuvers that threaten safety and mission success. We disclosed PCSPOOF to aerospace companies using TTE, and several are implementing mitigations from this paper.