A Procrastinating Control-Flow Integrity Framework for Periodic Real-Time Systems

A Procrastinating Control-Flow Integrity Framework for Periodic Real-Time Systems
复制标题

DOI:
10.1145/3575757.3575762
复制
发表时间:
2023-06
期刊:
Proceedings of the 31st International Conference on Real-Time Networks and Systems
影响因子:
--
通讯作者:
Tanmaya Mishra;Jinwen Wang;Thidapat Chantem;Ryan M. Gerdes;Ning Zhang
Tanmaya Mishra;Jinwen Wang;Thidapat Chantem;Ryan M. Gerdes;Ning Zhang
中科院分区:
其他
文献类型:
--
作者:
Tanmaya Mishra;Jinwen Wang;Thidapat Chantem;Ryan M. Gerdes;Ning Zhang

文献摘要

相似文献

连接的嵌入式系统和网络物理系统比孤立的系统表现出更大的攻击面。控制流完整性 (CFI) 是一组通过检测和检查控制流传输来防止攻击者重定向程序控制流并执行任意计算的技术。目前,实时系统的 CFI 要么与代码执行一致运行,通常依赖于硬件机制来提高性能和/或安全保证,要么在无序执行 CFI 时仅关注预算管理。在这项工作中,我们利用周期性实时系统的可预测发布模式来创建一个新颖的 CFI 框架。该框架 (1) 由一个新颖的实时任务模型组成,该模型明确考虑与 CFI 相关的执行以及任务的常规部分,并且 (2) 提出了一种新颖的硬件辅助可信调度程序,以分别在前向边缘和后向边缘上实现无序和内联控制流实施的独特组合,以最大限度地减少性能开销,同时确保实时期限。我们的框架提供了将任意前沿CFI建模为安全任务的灵活性,以便我们可以战略性地调度它们,并提供可调度性和正确性分析,以明确确保CFI验证始终按时执行,而不影响实时任务的及时性。模拟表明,我们的新任务模型在资源使用方面优于现有工作,从而允许实施更复杂和精密的 CFI。我们在真实硬件上实施我们的方法,微基准测试证实我们的方法具有与现有工作相当的在线开销。
Connected embedded systems and cyber-physical systems exhibit larger attack surface than isolated ones. Control-flow integrity (CFI) is a set of techniques to prevent attackers from redirecting program control-flow and performing arbitrary computation, by detecting and checking control-flow transfers. Currently CFI for real-time systems either operate in-line with code execution, often depending on hardware mechanisms for improved performance and/or security guarantees, or focus solely on budget management when performing CFI out-of-order. In this work, we exploit the predictable release pattern of periodic real-time systems to create a novel CFI framework. This framework (1) consists of a novel real-time task model, which explicitly considers CFI related execution along with the regular portion of the tasks, and (2) presents a novel hardware-assisted trusted scheduler to enable a unique combination of out-of-order and in-line control flow enforcement on forward edge and backwards edge, respectively, to minimize performance overhead while ensuring real-time deadlines. Our framework provides the flexibility to model arbitrary forward-edge CFI as security tasks, so that we may strategically schedule them, and provide schedulability and correctness analysis to explicitly ensure that CFI verification is always performed on time without affecting the timeliness of the real-time tasks. Simulations show that our new task model outperforms existing work in terms of resource usage, thus allowing for more complex and sophisticated CFI to be implemented. We implement our approach on real hardware and microbenchmarks confirm that our approach has comparable in-line overhead as existing work.