首页> 外文会议>Computer security >Enforcing Memory Safety in Cyber-Physical Systems
【24h】

Enforcing Memory Safety in Cyber-Physical Systems

机译:加强网络物理系统中的内存安全

获取原文
获取原文并翻译 | 示例

摘要

Cyber-Physical Systems (CPS) integrate computations and communications with physical processes and are being widely adopted in various application areas. However, the increasing prevalence of cyber attacks targeting them poses a growing security concern. In particular, attacks exploiting memory-safety vulnerabilities constitute a major attack vector against CPS, because embedded systems often rely on unsafe but fast programming languages to meet their hard time constraints. A wide range of countermeasures has been developed to provide protection against these attacks. However, the most reliable counter-measures incur in high runtime overheads. In this work, we explore the applicability of strong countermeasures against memory-safety attacks in the context of realistic Industrial Control Systems (ICS). To this end, we design an experimental setup, based on a secure water treatment plant (SWaT) to empirically measure the memory safety overhead (MSO) caused by memory-safe compilation of the Programmable Logic Controller (PLC). We then quantify the tolerability of this overhead in terms of the expected real-time constraints of SWaT. Our results show high effectiveness of the security measure in detecting memory-safety violations and a MSO (197.86 μs per scan-cycle) that is also tolerable for the SWaT simulation. We also discuss how different parameters impact the execution time of PLCs and the resulting absolute MSO.
机译:网络物理系统(CPS)将计算和通信与物理过程集成在一起,并在各种应用领域中被广泛采用。但是,针对它们的网络攻击的日益普遍引起对安全性的日益关注。特别是,利用内存安全漏洞的攻击构成了针对CPS的主要攻击媒介,因为嵌入式系统通常依赖于不安全但快速的编程语言来满足其困难的时间限制。已经开发出多种对策来提供针对这些攻击的保护。但是,最可靠的对策会增加运行时开销。在这项工作中,我们探索在现实的工业控制系统(ICS)的背景下针对内存安全攻击的强大对策的适用性。为此,我们设计了一个基于安全水处理厂(SWaT)的实验装置,以经验方式测量由可编程逻辑控制器(PLC)的内存安全编译引起的内存安全开销(MSO)。然后,我们根据SWaT的预期实时约束来量化此开销的可容忍性。我们的结果表明,该安全措施在检测内存安全违规方面具有很高的效率,并且MSO(每个扫描周期为197.86μs)对于SWaT模拟也是可以容忍的。我们还将讨论不同的参数如何影响PLC的执行时间以及产生的绝对MSO。

著录项

  • 来源
    《Computer security》|2017年|127-144|共18页
  • 会议地点 Oslo(NO)
  • 作者单位

    Singapore University of Technology and Design, Singapore, Singapore,Advanced Digital Sciences Center, Singapore, Singapore;

    Singapore University of Technology and Design, Singapore, Singapore;

    Singapore University of Technology and Design, Singapore, Singapore;

    Singapore University of Technology and Design, Singapore, Singapore,Advanced Digital Sciences Center, Singapore, Singapore;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号