首页> 外文会议>Design, Automation and Test in Europe Conference and Exhibition >Towards Malicious Exploitation of Energy Management Mechanisms
【24h】

Towards Malicious Exploitation of Energy Management Mechanisms

机译:走向能源管理机制的恶意利用

获取原文

摘要

Architectures are becoming more and more complex to keep up with the increase of algorithmic complexity. To fully exploit those architectures, dynamic resources managers are required. The goal of dynamic managers is either to optimize the resource usage (e.g. cores, memory) or to reduce energy consumption under performance constraints. However, performance optimization being their main goal, they have not been designed to be secure and present vulnerabilities. Recently, it has been proven that energy managers can be exploited to cause faults within a processor allowing to steal information from a user device. However, this exploitation is not often possible in current commercial devices. In this work, we show current security vulnerabilities through another type of malicious usage of energy management, experimentation shows that it is possible to remotely lock out a device, denying access to all services and data, requiring for example the user to pay a ransom to unlock it. The main target of this exploit are embedded systems and we demonstrate this work by its implementation on two different commercial ARM-based devices.
机译:为了跟上算法复杂性的增长,架构变得越来越复杂。为了充分利用这些架构,需要动态资源管理器。动态管理器的目标是优化资源使用(例如核心,内存)或在性能限制下降低能耗。但是,性能优化是其主要目标,但尚未将它们设计为安全并存在漏洞。最近,已经证明可以利用能量管理器在处理器内引起故障,从而允许从用户设备中窃取信息。但是,在当前的商用设备中这种开发通常是不可能的。在这项工作中,我们通过能源管理的另一种恶意使用方式展示了当前的安全漏洞,实验表明,可以远程锁定设备,拒绝访问所有服务和数据,例如,要求用户支付赎金以实现安全性。解锁。该漏洞利用的主要目标是嵌入式系统,我们通过在两种不同的基于ARM的商业设备上的实现来演示此工作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号