Building Embedded Systems Like It's 1996

Building Embedded Systems Like It's 1996
复制标题

DOI:
10.48550/arxiv.2203.06834
复制
发表时间:
2022-03
期刊:
ArXiv
影响因子:
--
通讯作者:
Ruotong Yu;Francesca Del Nin;Yuchen Zhang;Shan Huang;Pallavi Kaliyar;Sarah Zakto;M. Conti;G. Portokalidis;Jun Xu
Ruotong Yu;Francesca Del Nin;Yuchen Zhang;Shan Huang;Pallavi Kaliyar;Sarah Zakto;M. Conti;G. Portokalidis;Jun Xu
中科院分区:
其他
文献类型:
--
作者:
Ruotong Yu;Francesca Del Nin;Yuchen Zhang;Shan Huang;Pallavi Kaliyar;Sarah Zakto;M. Conti;G. Portokalidis;Jun Xu

文献摘要

相似文献

嵌入式设备无处不在。然而,初步证据表明,保护我们的桌面/服务器/手机的攻击缓解措施在嵌入式设备中缺失,对嵌入式安全构成了重大威胁。为此,本文对嵌入式设备采用常见攻击缓解措施进行了深入研究。准确地说,它在部署的嵌入式设备的超过10k基于linux的固件中测量针对内存损坏的标准缓解措施的存在。研究表明,嵌入式设备在很大程度上忽略了用户空间和内核级别的攻击缓解。嵌入式设备的采用率比桌面设备低很多倍。一个同样重要的观察是,情况并没有随着时间的推移而改善。如果不改变目前的做法,攻击缓解措施将仍然缺失,这可能成为即将到来的物联网时代的更大威胁。在后续分析中,我们进一步推断出一组可能导致攻击缓解措施缺失的因素。典型的问题包括大量重用不受保护的软件,延迟升级过时的内核,以及自动化构建工具施加的限制。我们预计这些将成为未来改进嵌入式设备攻击缓解采用的见解。
Embedded devices are ubiquitous. However, preliminary evidence shows that attack mitigations protecting our desktops/servers/phones are missing in embedded devices, posing a significant threat to embedded security. To this end, this paper presents an in-depth study on the adoption of common attack mitigations on embedded devices. Precisely, it measures the presence of standard mitigations against memory corruptions in over 10k Linux-based firmware of deployed embedded devices. The study reveals that embedded devices largely omit both user-space and kernel-level attack mitigations. The adoption rates on embedded devices are multiple times lower than their desktop counterparts. An equally important observation is that the situation is not improving over time. Without changing the current practices, the attack mitigations will remain missing, which may become a bigger threat in the upcoming IoT era. Throughout follow-up analyses, we further inferred a set of factors possibly contributing to the absence of attack mitigations. The exemplary ones include massive reuse of non-protected software, lateness in upgrading outdated kernels, and restrictions imposed by automated building tools. We envision these will turn into insights towards improving the adoption of attack mitigations on embedded devices in the future.