首页> 外文会议>International conference on computer design >Integrating Cyber-Attack Defense Techniques into Real-Time Cyber-Physical Systems
【24h】

Integrating Cyber-Attack Defense Techniques into Real-Time Cyber-Physical Systems

机译:将网络攻击防御技术集成到实时网络物理系统中

获取原文

摘要

With the rapid deployment of Cyber-Physical Systems (CPS), security has become a more critical problem than ever before, as such devices are interconnected and have access to a broad range of critical data. A well-known attack is ReturnOriented Programming (ROP) which can diverge the control flow of a program by exploiting the buffer overflow vulnerability. To protect a program from ROP attacks, a useful method is to instrument code into the protected program to do runtime control flow checking (known as Control Flow Integrity, CFI). However, instrumented code brings extra execution time, which has to be properly handled, as most CPS systems need to behave in a real-time manner. In this paper, we present a technique to efficiently compute an execution plan, which maximizes the number of executions of instrumented code to achieve maximal defense effect, and at the same time guarantees real-time schedulability of the protected task system with a new response time analysis. Simulation-based experimental results show that the proposed method can yield good quality execution plans, but performs orders of magnitude faster than exhaustive search. We also built a prototype in which a small auto-drive car is defended against ROP attacks by the proposed method implemented in FreeRTOS. The prototype demonstrates the effectiveness of our method in real-life scenarios.
机译:随着网络物理系统(CPS)的快速部署,由于这种设备互连并可访问广泛的关键数据,安全性已成为比以前更关键的问题。众所周知的攻击是返回返回程序的编程(ROP),可以通过利用缓冲区溢出漏洞来分歧程序的控制流程。要保护程序从ROP攻击中保护程序,有用的方法是将代码介绍到受保护程序中,以进行运行时控制流程检查(称为控制流程完整性,CFI)。但是,由于大多数CPS系统需要以实时方式表现,因此,仪表代码带来了额外的执行时间,这必须适当处理。在本文中,我们提出了一种技术来有效地计算执行计划,这使得仪表代码的执行次数最大化以实现最大防御效果,并且同时保证受保护的任务系统的实时调度性具有新的响应时间分析。基于仿真的实验结果表明,该方法可以产生良好的质量执行计划,但比详尽的搜索更快地执行数量级。我们还建立了一种原型,其中一辆小型自动驾驶汽车通过在Freertos中实现的建议方法对ROP攻击进行辩护。原型演示了我们在现实生活中的方法的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号