Securing the Device Drivers of Your Embedded Systems: Framework and Prototype

Securing the Device Drivers of Your Embedded Systems: Framework and Prototype
复制标题

保护嵌入式系统的设备驱动程序:框架和原型

DOI:
10.1145/3339252.3340506
复制
发表时间:
2019
期刊:
Proceedings of the 14th International Conference on Availability, Reliability and Security
影响因子:
--
通讯作者:
John C.S. Lui
John C.S. Lui
中科院分区:
--
文献类型:
--
作者:
Zhuo Li;Jincheng Wang;Mingshen Sun;John C.S. Lui

文献摘要

被引文献

相似文献

基于Linux的嵌入式或物联网系统上的设备驱动程序在内核空间执行,因此必须完全可信。驱动程序中的任何故障都可能严重影响整个系统。但是,第三方嵌入式硬件制造商通常会随其嵌入式设备提供专有设备驱动程序。由于缺乏代码审核,这些树外设备驱动程序通常质量很差。在本文中,我们提出了一种新的方法,可以帮助第三方开发人员在不修改内核的情况下提高设备驱动程序的可靠性和安全性:用一种名为Rust的内存安全编程语言重写设备驱动程序。Rust严格的语言模型帮助设备驱动程序开发人员在编译时检测许多安全问题。我们设计了一个框架来帮助开发人员在Rust中快速构建设备驱动程序。我们还利用Rust的安全特性为开发人员提供了几个有用的基础设施,以便他们可以轻松处理内核内存分配和并发管理,同时可以减轻一些常见的错误(例如释放后使用)。我们通过在Raspberry Pi 3上实现一个真实世界的设备驱动程序来证明我们框架的通用性,我们的评估表明,由我们框架生成的设备驱动程序对于规范的嵌入式系统具有可接受的二进制大小,并且运行时开销可以忽略不计。
Device drivers on Linux-powered embedded or IoT systems execute in kernel space thus must be fully trusted. Any fault in drivers may significantly impact the whole system. However, third-party embedded hardware manufacturers usually ship their proprietary device drivers with their embedded devices. These out-of-tree device drivers are generally of poor quality because of a lack of code audit. In this paper, we propose a new approach that helps third-party developers to improve the reliability and safety of device drivers without modifying the kernel: Rewriting device drivers in a memory-safe programming language called Rust. Rust's rigorous language model assists the device driver developers to detect many security issues at compile time. We designed a framework to help developers to quickly build device drivers in Rust. We also utilized Rust's security features to provide several useful infrastructures for developers so that they can easily handle kernel memory allocation and concurrency management, at the same time, some common bugs (e.g. use-after-free) can be alleviated. We demonstrate the generality of our framework by implementing a real-world device driver on Raspberry Pi 3, and our evaluation shows that device drivers generated by our framework have acceptable binary size for canonical embedded systems and the runtime overhead is negligible.