首页> 外文会议>International Symposium on Microarchitecture >Software-based Gate-level Information Flow Security for IoT Systems
【24h】

Software-based Gate-level Information Flow Security for IoT Systems

机译:IOT系统的基于软件的门级信息流安全

获取原文

摘要

The growing movement to connect literally everything to the internet (internet of things or IoT) through ultra-low-power embedded microprocessors poses a critical challenge for information security. Gate-level tracking of information flows has been proposed to guarantee information flow security in computer systems. However, such solutions rely on non-commodity, secure-by-design processors. In this work, we observe that the need for secure-by-design processors arises because previous works on gate-level information flow tracking assume no knowledge of the application running in a system. Since IoT systems typically run a single application over and over for the lifetime of the system, we see a unique opportunity to provide application-specific gate-level information flow security for IoT systems. We develop a gate-level symbolic analysis framework that uses knowledge of the application running in a system to efficiently identify all possible information flow security vulnerabilities for the system. We leverage this information to provide security guarantees on commodity processors. We also show that security vulnerabilities identified by our analysis framework can be eliminated through software modifications at 15% energy overhead, on average, obviating the need for secure-by-design hardware. Our framework also allows us to identify and eliminate only the vulnerabilities that an application is prone to, reducing the cost of information flow security by 3.3× compared to a software-based approach that assumes no application knowledge.
机译:通过超低功耗嵌入式微处理器对互联网(物联网或物联网或物联网)来说越来越多的运动对信息安全构成了危急挑战。已经提出了信息流的门级跟踪,以保证计算机系统中的信息流安全性。但是,这种解决方案依赖于非商品,逐个设计的处理器。在这项工作中,我们观察到,对安全旁观设计处理器的需求产生,因为之前的门级信息流跟踪的工作不知道系统中运行的应用程序。由于IOT系统通常在系统的生命周围运行单个应用程序,因此我们可以看到为IOT系统提供特定于应用的门级信息流安全的独特机会。我们开发了一个门级符号分析框架,它使用系统中运行的应用程序的知识来有效地识别系统的所有可能的信息流安全漏洞。我们利用这些信息提供商品处理器的安全保障。我们还表明,通过平均的软件修改,可以通过45%能量开销,避免对安全逐个硬件的需求来消除我们的分析框架的安全漏洞。我们的框架还允许我们仅识别和消除应用程序倾向于的漏洞,与假设没有应用知识的基于软件的方法,将信息流安全性的成本降低3.3倍。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号