Capture: Centralized Library Management for Heterogeneous IoT Devices

Capture: Centralized Library Management for Heterogeneous IoT Devices
复制标题

DOI:
--
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
Han Zhang;Abhijith Anilkumar;Matt Fredrikson;Yuvraj Agarwal
Han Zhang;Abhijith Anilkumar;Matt Fredrikson;Yuvraj Agarwal
中科院分区:
其他
文献类型:
--
作者:
Han Zhang;Abhijith Anilkumar;Matt Fredrikson;Yuvraj Agarwal

文献摘要

相似文献

随着物联网 (IoT) 设备的日益普及,它已成为有吸引力的攻击目标。与大多数现代软件系统一样,物联网设备固件广泛依赖于外部第三方库,增加了物联网设备的攻击面。此外,我们发现,设备供应商不一致的库管理实践和应用安全更新的延迟(有时比公开发布关键补丁晚了数百天)加剧了风险。更糟糕的是,由于这些依赖关系被“嵌入”供应商控制的固件中,因此即使具有安全意识的用户也无法在良好的安全卫生方面将问题掌握在自己手中。我们提出了 Capture ,这是一种用于部署物联网设备固件的新颖架构,它允许本地网络上的设备利用带有第三方库的集中式集线器来解决这个问题,这些第三方库由单个可信实体进行管理和保持最新状态。支持 Capture 的 IoT 设备由两个组件组成:设备上支持 Capture 的固件和使用本地网络中 Capture 中心上的第三方库的远程驱动程序。为了确保隔离,我们引入了一种新颖的虚拟设备实体(VDE)接口,该接口有助于驻留在同一集线器上的相互不信任的设备之间的访问控制。我们对 Capture 原型实现以及移植到我们框架的 9 个设备和 3 个自动化小程序的评估表明,我们的方法在大多数情况下产生的开销较低(延迟增加 < 15%,额外资源 < 10%)。我们证明,具有适度硬件的单个 Capture Hub 可以支持数百个设备,并保持其共享库最新。
With their growing popularity, Internet-of-Things (IoT) devices have become attractive targets for attack. Like most modern software systems, IoT device firmware depends on external third-party libraries extensively, increasing the attack surface of IoT devices. Furthermore, we find that the risk is compounded by inconsistent library management practices and delays in applying security updates—sometimes hundreds of days behind the public availability of critical patches—by device vendors. Worse yet, because these dependencies are “baked into” the vendor-controlled firmware, even security-conscious users are unable to take matters into their own hands when it comes to good security hygiene. We present Capture , a novel architecture for deploying IoT device firmware that addresses this problem by allowing devices on a local network to leverage a centralized hub with third-party libraries that are managed and kept up-to-date by a single trusted entity. An IoT device supporting Capture comprises of two components: Capture-enabled firmware on the device and a remote driver that uses third-party libraries on the Capture hub in the local network. To ensure isolation, we introduce a novel Virtual Device Entity (VDE) interface that facilitates access control between mutually-distrustful devices that reside on the same hub. Our evaluation on a prototype implementation of Capture, along with 9 devices and 3 automation applets ported to our framework, shows that our approach incurs low overhead in most cases ( < 15% increased latency, < 10% additional resources). We show that a single Capture Hub with modest hardware can support hundreds of devices, keeping their shared libraries up-to-date.