SchedGuard++: Protecting against Schedule Leaks Using Linux Containers on Multi-Core Processors

SchedGuard++: Protecting against Schedule Leaks Using Linux Containers on Multi-Core Processors
复制标题

DOI:
10.1145/3565974
复制
发表时间:
2022-10
影响因子:
2.3
通讯作者:
Jiyang Chen;Tomasz Kloda;Rohan Tabish;Ayoosh Bansal;Chien-Ying Chen;Bo Liu;Sibin Mohan;Marco Caccamo-M
Jiyang Chen;Tomasz Kloda;Rohan Tabish;Ayoosh Bansal;Chien-Ying Chen;Bo Liu;Sibin Mohan;Marco Caccamo-M
中科院分区:
--
文献类型:
--
作者:
Jiyang Chen;Tomasz Kloda;Rohan Tabish;Ayoosh Bansal;Chien-Ying Chen;Bo Liu;Sibin Mohan;Marco Caccamo-M

文献摘要

相似文献

在诸如自动驾驶系统等多关键级实时系统中,时序正确性至关重要。最近已表明,这些系统可能容易受到时序推理攻击,这主要是由于其可预测的行为模式。像调度随机化这样的现有解决方案无法抵御此类攻击,往往受到系统实时性的限制。本文介绍了“SchedGuard++”:一个基于Linux的实时系统的时间保护框架,它通过防止不可信任务在特定时间间隔内执行来抵御基于后置调度的攻击。SchedGuard++支持多核平台,并使用Linux容器和定制的Linux内核实时调度器实现。我们在假设逻辑执行时间(LET)范式的情况下提供可调度性分析,该范式强制I/O可预测性。所提出的响应时间分析考虑了来自可信和不可信任务的干扰以及保护机制的影响。我们使用一个真实的无线电控制漫游车平台展示了我们系统的有效性。“SchedGuard++”不仅能够抵御基于后置调度的攻击,而且还确保实时任务/容器满足其时间要求。
Timing correctness is crucial in a multi-criticality real-time system, such as an autonomous driving system. It has been recently shown that these systems can be vulnerable to timing inference attacks, mainly due to their predictable behavioral patterns. Existing solutions like schedule randomization cannot protect against such attacks, often limited by the system’s real-time nature. This article presents “SchedGuard++”: a temporal protection framework for Linux-based real-time systems that protects against posterior schedule-based attacks by preventing untrusted tasks from executing during specific time intervals. SchedGuard++ supports multi-core platforms and is implemented using Linux containers and a customized Linux kernel real-time scheduler. We provide schedulability analysis assuming the Logical Execution Time (LET) paradigm, which enforces I/O predictability. The proposed response time analysis takes into account the interference from trusted and untrusted tasks and the impact of the protection mechanism. We demonstrate the effectiveness of our system using a realistic radio-controlled rover platform. Not only is “SchedGuard++” able to protect against the posterior schedule-based attacks, but it also ensures that the real-time tasks/containers meet their temporal requirements.