Security-Aware Scheduling of Embedded Control Tasks

Security-Aware Scheduling of Embedded Control Tasks
复制标题

DOI:
10.1145/3126518
复制
发表时间:
2017-09
期刊:
ACM Transactions on Embedded Computing Systems (TECS)
影响因子:
--
通讯作者:
Vuk Lesi;Ilija Jovanov;Miroslav Pajic
Vuk Lesi;Ilija Jovanov;Miroslav Pajic
中科院分区:
其他
文献类型:
--
作者:
Vuk Lesi;Ilija Jovanov;Miroslav Pajic

文献摘要

相似文献

在这项工作中,我们专注于在存在基于网络的攻击的情况下保护网络物理系统(CPS),例如中间人(MitM)攻击,其中隐形攻击者能够破坏系统传感器和控制器之间的通信。这类攻击的标准方法依赖于使用加密机制,例如消息身份验证码(mac)来确保数据完整性。然而,这种方法带来了巨大的计算开销,限制了它在资源受限系统中的使用。因此,我们考虑在提供适当级别的安全保证的同时在共享处理器上调度多个控制任务的问题。具体来说,通过安全保证,我们指的是存在攻击时的控制性能,即控制质量(Quality-of-Control, QoC)。我们首先将攻击下的QoC需求映射到安全感知控制任务的约束中,这些控制任务除了标准控制操作外,还间歇性地执行数据身份验证。这允许分析与安全相关的计算开销对控制任务的可调度性和qos的影响。在此分析的基础上,我们引入了一种基于混合整数线性规划的技术,以获得具有预定义QoC需求的可调度任务集。此外,为了实现最优资源分配,我们提供了一种方法来分析可用计算资源与受攻击的总体qos之间的相互作用,并展示了如何获得最大化总体qos保证的可调度任务集。最后,我们在多个汽车控制组件的案例研究中证明了我们方法的可用性。
In this work, we focus on securing cyber-physical systems (CPS) in the presence of network-based attacks, such as Man-in-the-Middle (MitM) attacks, where a stealthy attacker is able to compromise communication between system sensors and controllers. Standard methods for this type of attacks rely on the use of cryptographic mechanisms, such as Message Authentication Codes (MACs) to ensure data integrity. However, this approach incurs significant computation overhead, limiting its use in resource constrained systems. Consequently, we consider the problem of scheduling multiple control tasks on a shared processor while providing a suitable level of security guarantees. Specifically, by security guarantees we refer to control performance, i.e., Quality-of-Control (QoC), in the presence of attacks. We start by mapping requirements for QoC under attack into constraints for security-aware control tasks that, besides standard control operations, intermittently perform data authentication. This allows for the analysis of the impact that security-related computation overhead has on both schedulability of control tasks and QoC. Building on this analysis, we introduce a mixed-integer linear programming-based technique to obtain a schedulable task set with predefined QoC requirements. Also, to facilitate optimal resource allocation, we provide a method to analyze interplay between available computational resources and the overall QoC under attack, and show how to obtain a schedulable task set that maximizes the overall QoC guarantees. Finally, we prove usability of our approach on a case study with multiple automotive control components.