Umbra: Embedded Web Security Through Application-Layer Firewalls
Umbra: Embedded Web Security Through Application-Layer Firewalls
复制标题
Umbra:通过应用层防火墙实现嵌入式网络安全
DOI:
--
复制
发表时间:
2015
期刊:
影响因子:
--
通讯作者:
J. A. Halderman
中科院分区:
文献类型:
--
作者:
Travis Finkenauer;J. A. Halderman
Embedded devices with web interfaces are prevalent, but, due to memory and processing constraints, implementations typically make use of Common Gateway Interface (CGI) binaries written in low-level, memory-unsafe languages. This creates the possibility of memory corruption attacks as well as traditional web attacks. We present Umbra, an application-layer firewall specifically designed for protecting web interfaces in embedded devices. By acting as a “friendly man-in-the-middle,” Umbra can protect against attacks such as cross-site request forgery (CSRF), information leaks, and authentication bypass vulnerabilities. We evaluate Umbra’s security by analyzing recent vulnerabilities listed in the CVE database from several embedded vendors and find that it would have prevented half of the vulnerabilities. We also show that Umbra comfortably runs within the constraints of an embedded system while incurring minimal performance overhead.