One size does not fit all: security hardening of MIPS embedded systems via static binary debloating for shared libraries

One size does not fit all: security hardening of MIPS embedded systems via static binary debloating for shared libraries
复制标题

DOI:
10.1145/3503222.3507768
复制
发表时间:
2022-02
期刊:
Proceedings of the 27th ACM International Conference on Architectural Support for Programming Languages and Operating Systems
影响因子:
--
通讯作者:
Haotian Zhang;Mengfei Ren;Yu Lei;Jiang Ming
Haotian Zhang;Mengfei Ren;Yu Lei;Jiang Ming
中科院分区:
其他
文献类型:
--
作者:
Haotian Zhang;Mengfei Ren;Yu Lei;Jiang Ming

文献摘要

相似文献

嵌入式系统已成为网络攻击的主要目标。为了利用固件的内存损坏漏洞,网络犯罪分子从大型共享库代码库(例如,uClibc)。不幸的是,与桌面系统不同,嵌入式系统缺乏必要的计算资源来实施安全加固技术。最近,我们已经目睹了一个软件debloading作为一种新的防御机制,对代码重用攻击的激增;它删除未使用的代码,显着减少构造可重用的小工具的可能性。由于单一的固件映像更新风格,静态库debloading显示出在不损害性能和向前兼容性的情况下增强嵌入式系统的前景。然而,在剥离的二进制文件上的静态库解浮动(例如,固件的共享库)仍然是一个巨大的挑战。在本文中,我们表明,这一挑战是不是不可逾越的MIPS固件。我们开发了一个名为uTrimmer的新颖系统,用于识别并消除共享库二进制代码中未使用的基本块,而不会导致额外的运行时开销或内存消耗。我们提出了一种新的方法来识别地址占用块/函数,这进一步帮助我们维护一个过程间控制流图,以保守地包括可能被固件使用的库代码。通过捕获位置无关代码的地址访问模式,我们规避了确定代码指针目标的挑战,并安全地消除未使用的代码。我们运行uTrimmer来卸载SPEC CPU 2017基准测试的共享库,流行的固件应用程序(例如,Apache、BusyBox和OpenSSL),以及一个真实的无线路由器固件映像。我们的实验表明,uTrimmer不仅交付功能程序,而且它可以削减暴露的代码表面,并消除各种可重用的代码小工具显着。uTrimmer的解浮动能力可以与静态链接结果竞争。
Embedded systems have become prominent targets for cyberattacks. To exploit firmware’s memory corruption vulnerabilities, cybercriminals harvest reusable code gadgets from the large shared library codebase (e.g., uClibc). Unfortunately, unlike their desktop counterparts, embedded systems lack essential computing resources to enforce security hardening techniques. Recently, we have witnessed a surge of software debloating as a new defense mechanism against code-reuse attacks; it erases unused code to significantly diminish the possibilities of constructing reusable gadgets. Because of the single firmware image update style, static library debloating shows promise to fortify embedded systems without compromising performance and forward compatibility. However, static library debloating on stripped binaries (e.g., firmware’s shared libraries) is still an enormous challenge. In this paper, we show that this challenge is not insurmountable for MIPS firmware. We develop a novel system, named uTrimmer, to identify and wipe out unused basic blocks from shared libraries’ binary code, without causing additional runtime overhead or memory consumption. We propose a new method to identify address-taken blocks/functions, which further help us maintain an inter-procedural control flow graph to conservatively include library code that could be potentially used by firmware. By capturing address access patterns for position-independent code, we circumvent the challenge of determining code-pointer targets and safely eliminate unused code. We run uTrimmer to debloat shared libraries for SPEC CPU2017 benchmarks, popular firmware applications (e.g., Apache, BusyBox, and OpenSSL), and a real-world wireless router firmware image. Our experiments show that not only does uTrimmer deliver functional programs, but also it can cut the exposed code surface and eliminate various reusable code gadgets remarkably. uTrimmer’s debloating capability can compete with the static linking results.