首页> 外文会议>International conference on computer design >Integrating Cyber-Attack Defense Techniques into Real-Time Cyber-Physical Systems
【24h】

Integrating Cyber-Attack Defense Techniques into Real-Time Cyber-Physical Systems

机译:将网络攻击防御技术集成到实时网络物理系统中

获取原文

摘要

With the rapid deployment of Cyber-Physical Systems (CPS), security has become a more critical problem than ever before, as such devices are interconnected and have access to a broad range of critical data. A well-known attack is ReturnOriented Programming (ROP) which can diverge the control flow of a program by exploiting the buffer overflow vulnerability. To protect a program from ROP attacks, a useful method is to instrument code into the protected program to do runtime control flow checking (known as Control Flow Integrity, CFI). However, instrumented code brings extra execution time, which has to be properly handled, as most CPS systems need to behave in a real-time manner. In this paper, we present a technique to efficiently compute an execution plan, which maximizes the number of executions of instrumented code to achieve maximal defense effect, and at the same time guarantees real-time schedulability of the protected task system with a new response time analysis. Simulation-based experimental results show that the proposed method can yield good quality execution plans, but performs orders of magnitude faster than exhaustive search. We also built a prototype in which a small auto-drive car is defended against ROP attacks by the proposed method implemented in FreeRTOS. The prototype demonstrates the effectiveness of our method in real-life scenarios.
机译:随着网络物理系统(CPS)的快速部署,安全性已成为比以往任何时候都更为严重的问题,因为此类设备相互连接并可以访问广泛的关键数据。众所周知的攻击是面向返回的编程(ROP),它可以通过利用缓冲区溢出漏洞来分散程序的控制流。为了保护程序免受ROP攻击,一种有用的方法是将代码插入受保护的程序中,以进行运行时控制流检查(称为控制流完整性,CFI)。但是,由于大多数CPS系统都需要以实时方式运行,因此检测代码会带来额外的执行时间,必须适当处理。在本文中,我们提出了一种有效地计算执行计划的技术,该技术可以最大化检测代码的执行次数以实现最大的防御效果,并同时保证受保护任务系统的实时可调度性并具有新的响应时间。分析。基于仿真的实验结果表明,该方法可以产生高质量的执行计划,但比穷举搜索要快几个数量级。我们还构建了一个原型,其中通过FreeRTOS中实现的拟议方法,使小型自动驾驶汽车免受ROP攻击。该原型演示了我们的方法在现实场景中的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号