CAREER: Indistinguishability Prevents Information Leakage in Real-Time Schedulers
CAREER: Indistinguishability Prevents Information Leakage in Real-Time Schedulers
批准号:
2145787
负责人:
Sibin Mohan
金额:
$52.34万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2022
资助国家:
美国
项目状态:
已结题
起止时间:
2022-06-01 至 2022-12-31
中文摘要
现代社会在很大程度上依赖于在严格的定时要求下运行的系统,例如汽车中的发动机控制单元、飞机航空电子设备和导航系统、制造工厂中的可编程逻辑控制器、电力部门的工业控制系统以及数百个其他系统。最近出现的自动驾驶汽车、无人机和物联网(IoT)进一步扩大了这些“实时系统”的范围。这种装置的局限性,即,小的计算能力、更少的内存、有限的电池电量,对安全性有严重的影响,具体地说,它们变得更加难以保护和防御。本研究为关键应用中的实时嵌入式系统开发了系统的安全机制,以控制可以观察到的内容。实时系统易受攻击的一个重要原因是它们在设计上是可预测的,因此会泄露关键信息。泄漏,比如说通过定时“边通道”,可能被滥用为活动的一部分,通过了解关键应用程序何时运行来破坏正常操作。 任何缓解信息泄漏的措施都必须允许实时系统在其所需的时间限制内运行。该项目利用为数据库安全而开发的差分隐私领域的概念来提高实时系统的安全性,其基本概念是通过以系统的方式注入“噪声”来隐藏大型数据库查询中的个人识别信息。通过对实时系统的类比,该项目专注于运行时的系统状态,并通过在任务调度器中策略性地添加“噪声”来开发“调度不可重复性”的概念,因此单个任务无法单独区分,也无法知道。通过对任务级行为的观察,提出了“ε-不可测性”的概念,以度量调度和定时信息的信息泄漏概率。一个任务调度器,有效地和高效地使用不可逆性的设计和原型。 此外,该项目的重点是开发实时系统的度量标准,以衡量和评估使用进度不可中断性的风险缓解。该研究的长期目标是探索网络物理系统及其应用领域在安全性、安全性、可靠性和弹性方面的“不可分割性”关系。该奖项反映了NSF的法定使命,通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Modern society relies heavily on systems that operate within strict timing requirements such as in engine control units in automobiles, aircraft avionics and navigation systems, programmable logic controllers in manufacturing plants, industrial control systems in the electricity sector, and many hundreds of others. The recent advent of autonomous cars, drones and internet-of-things (IoT) further expands the reach of these "real-time systems". The limitations of such devices viz., small computing power, less memory, limited battery power, has serious consequences for security, specifically, they become much harder to protect and defend. This research develops systematic security mechanisms for real-time embedded systems in critical applications to control what can be observed about them. An important reason why real-time systems are vulnerable is the fact that they are predictable by design, thus leaking critical information. Leakage, say via timing "side channels", might be misused as part of a campaign to disrupt normal operations by knowing the schedule of when critical applications will run. Any mitigations to information leakage must still allow real-time systems to operate within their required timing constraints. This project improves the security of real-time systems using concepts inspired from the area of differential privacy that was developed for database security, where the fundamental concept is to hide personally identifying information from queries on large databases by injecting "noise" in a systematic manner. By analogy for real-time systems, this project focuses on system states at runtime and develops the notion of "schedule indistinguishability" by strategically adding "noise" to the task scheduler, so individual tasks cannot be distinguished separately and cannot be known. The concept of "epsilon-indistinguishability" is developed to measure the probability of information leakage of schedule and timing information by observation of task-level behaviors. A task scheduler that effectively and efficiently uses indistinguishability is designed and prototyped. In addition, the project focuses on developing metrics for real-time systems to measure and assess the risk mitigations of using schedule indistinguishability. The long-term goal of this research is to explore the relationships of "indistinguishability" for cyber-physical systems and their application domains with regard to security, safety, dependability, and resilience.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1145/3565974
发表时间:
2022-10
期刊:
ACM Transactions on Cyber-Physical Systems
影响因子:
2.3
作者:
[Jiyang Chen;Tomasz Kloda;Rohan Tabish;Ayoosh Bansal;Chien-Ying Chen;Bo Liu;Sibin Mohan;Marco Caccamo-M]
通讯作者:
Jiyang Chen;Tomasz Kloda;Rohan Tabish;Ayoosh Bansal;Chien-Ying Chen;Bo Liu;Sibin Mohan;Marco Caccamo-M
Towards Efficient Auditing for Real-Time Systems.
实现实时系统的高效审计。
DOI:
--
发表时间:
2022
期刊:
27th European Symposium on Research in Computer Security
影响因子:
--
作者:
[Bansal, A., Kandikuppa, A., Chen, CY., Hasan, M., Bates, A., Mohan, S.]
通讯作者:
Mohan, S.
DOI:
10.1109/milcom55135.2022.10017482
发表时间:
2022-11
期刊:
MILCOM 2022 - 2022 IEEE Military Communications Conference (MILCOM)
影响因子:
--
作者:
[K. Kim;Denizkhan Kara;V. Paruchuri;Sibin Mohan;Greg Kimberly;Denis Osipychev;Jae H. Kim;Josh D. Eckha]
通讯作者:
K. Kim;Denizkhan Kara;V. Paruchuri;Sibin Mohan;Greg Kimberly;Denis Osipychev;Jae H. Kim;Josh D. Eckha
CAREER: Indistinguishability Prevents Information Leakage in Real-Time Schedulers
-
批准号:2246937
-
项目类别:Continuing Grant
-
资助金额:$52.34万
-
财政年份:2022
-
负责人:Sibin Mohan
-
依托单位:
SaTC: CORE: Small: An Exploration of Schedule-Based Vulnerabilities In Real-Time Embedded Systems
-
批准号:1718952
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2017
-
负责人:Sibin Mohan
-
依托单位:
CPS: TTP Option: Frontiers: Collaborative Research: Software Defined Control for Smart Manufacturing Systems
-
批准号:1544901
-
项目类别:Continuing Grant
-
资助金额:$112.5万
-
财政年份:2016
-
负责人:Sibin Mohan
-
依托单位:
TWC: Small: Behavior-Based Zero-Day Intrusion Detection for Real-Time Cyber-Physical Systems
-
批准号:1423334
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2014
-
负责人:Sibin Mohan
-
依托单位:
海外基金