Trick or Heat?: Manipulating Critical Temperature-Based Control Systems Using Rectification Attacks

Trick or Heat?: Manipulating Critical Temperature-Based Control Systems Using Rectification Attacks
复制标题

DOI:
10.1145/3319535.3354195
复制
发表时间:
2019-04
期刊:
Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Yazhou Tu;Sara Rampazzi;Bin Hao;Angel Rodriguez;Kevin Fu;X. Hei
Yazhou Tu;Sara Rampazzi;Bin Hao;Angel Rodriguez;Kevin Fu;X. Hei
中科院分区:
其他
文献类型:
--
作者:
Yazhou Tu;Sara Rampazzi;Bin Hao;Angel Rodriguez;Kevin Fu;X. Hei

文献摘要

被引文献

相似文献

温度传感和控制系统广泛用于关键过程的闭环控制,例如保持患者的热稳定性,或用于检测温度相关危险的报警系统。然而,这些系统的安全性尚未完全探索,留下了可以被利用来控制关键系统的潜在攻击面。在本文中,我们调查的可靠性基于温度的控制系统从安全和安全的角度。我们展示了如何通过对模拟温度传感元件的物理级攻击来引发意想不到的后果和安全风险。例如,我们证明了对手可以远程操纵婴儿保温箱的温度传感器测量结果,从而导致潜在的安全问题,而不会篡改受害者系统或触发自动温度警报。这种攻击利用了运算放大器和仪表放大器中可能产生的非预期整流效应来控制传感器输出,从而欺骗受害系统的内部控制环路来加热或冷却。此外,我们展示了如何利用这种硬件级漏洞可能会影响不同类别的模拟传感器,共享类似的信号调理过程。我们的实验结果表明,通常部署在这些系统中的传统防御不足以减轻威胁,因此我们提出了一个低成本的异常检测器的原型设计,用于关键应用,以确保温度传感器信号的完整性。
Temperature sensing and control systems are widely used in the closed-loop control of critical processes such as maintaining the thermal stability of patients, or in alarm systems for detecting temperature-related hazards. However, the security of these systems has yet to be completely explored, leaving potential attack surfaces that can be exploited to take control over critical systems. In this paper we investigate the reliability of temperature-based control systems from a security and safety perspective. We show how unexpected consequences and safety risks can be induced by physical-level attacks on analog temperature sensing components. For instance, we demonstrate that an adversary could remotely manipulate the temperature sensor measurements of an infant incubator to cause potential safety issues, without tampering with the victim system or triggering automatic temperature alarms. This attack exploits the unintended rectification effect that can be induced in operational and instrumentation amplifiers to control the sensor output, tricking the internal control loop of the victim system to heat up or cool down. Furthermore, we show how the exploit of this hardware-level vulnerability could affect different classes of analog sensors that share similar signal conditioning processes. Our experimental results indicate that conventional defenses commonly deployed in these systems are not sufficient to mitigate the threat, so we propose a prototype design of a low-cost anomaly detector for critical applications to ensure the integrity of temperature sensor signals.