Umbra: Embedded Web Security Through Application-Layer Firewalls

Umbra: Embedded Web Security Through Application-Layer Firewalls
复制标题

Umbra:通过应用层防火墙实现嵌入式网络安全

DOI:
--
复制
发表时间:
2015
期刊:
CyberICS/WOS-CPS@ESORICS
影响因子:
--
通讯作者:
J. A. Halderman
J. A. Halderman
中科院分区:
--
文献类型:
--
作者:
Travis Finkenauer;J. A. Halderman

文献摘要

被引文献

相似文献

具有Web接口的嵌入式设备很普遍,但是由于内存和处理限制,实现通常使用以低级内存不安全语言编写的通用网关接口(CGI)二进制文件。这可能会造成内存损坏攻击以及传统的Web攻击。我们提出了Umbra,一个专门为保护嵌入式设备中的Web接口而设计的应用层防火墙。通过充当“友好的中间人”,Umbra可以防止跨站点请求伪造(CSRF)、信息泄漏和身份验证绕过漏洞等攻击。我们通过分析几个嵌入式供应商的CVE数据库中列出的最新漏洞来评估Umbra的安全性,并发现它可以防止一半的漏洞。我们还表明,Umbra舒适地运行在嵌入式系统的约束,同时产生最小的性能开销。
Embedded devices with web interfaces are prevalent, but, due to memory and processing constraints, implementations typically make use of Common Gateway Interface (CGI) binaries written in low-level, memory-unsafe languages. This creates the possibility of memory corruption attacks as well as traditional web attacks. We present Umbra, an application-layer firewall specifically designed for protecting web interfaces in embedded devices. By acting as a “friendly man-in-the-middle,” Umbra can protect against attacks such as cross-site request forgery (CSRF), information leaks, and authentication bypass vulnerabilities. We evaluate Umbra’s security by analyzing recent vulnerabilities listed in the CVE database from several embedded vendors and find that it would have prevented half of the vulnerabilities. We also show that Umbra comfortably runs within the constraints of an embedded system while incurring minimal performance overhead.