...
首页> 外文期刊>IEEE Transactions on Sustainable Computing >Exploiting Battery-Drain Vulnerabilities in Mobile Smart Devices
【24h】

Exploiting Battery-Drain Vulnerabilities in Mobile Smart Devices

机译:利用移动智能设备中的电池耗电漏洞

获取原文
获取原文并翻译 | 示例
           

摘要

Differently from attacks aimed at gaining control of the resources of a mobile device, energy-related attacks have the essential goal of significantly raising the energy demand on the victim side, without apparently affecting its activities. It is a fundamental point to highlight how such a goal can possibly be accomplished by mounting well-known canonical attacks and waiting for the system defenses to detect and stop them. In such an endeavor, defenses require additional amounts of energy which eventually render the mobile device completely useless. In the System on Chip (SoC) architecture, many components, each with a separate function, are integrated. As the total energy adsorption is the composition of the energy consumptions of individual components, each component may be the target of an energy-based attack. This work analyzes and discusses the effects and implication of new energy-based Denial of Service attacks based on the proper solicitation of hardware-layer encode/decode capabilities by using specifically crafted multimedia resources, in order to introduce an anomalous battery drain, and hence significantly shorten the overall battery lifetime in mobile smart devices. These attacks do not require physical access nor compromise of the target device, and they take advantage of new HTML5 functionalities that can be properly triggered during normal browsing activity. The more significant result is that the Digital Signal Processor (DSP) offers an exploitable attack surface to be kept into consideration early in the design process. Countermeasures include special filtering rules that prevent “irrelevant” content from reaching the DSP or, in a more far-reached perspective, the introduction of a power-draw controller on the SoC with the purpose of monitoring energy consumption and raising alerts.
机译:与旨在获得对移动设备资源的控制的攻击不同,与能量相关的攻击的主要目标是显着提高受害方的能源需求,而不会明显影响其活动。重点是要强调如何通过发起众所周知的规范攻击并等待系统防御程序检测并阻止它们来实现这一目标。在这样的努力中,防御需要额外的能量,这最终使移动设备完全无用。在片上系统(SoC)架构中,集成了许多具有各自功能的组件。由于总的能量吸收是各个组件能耗的组成,因此每个组件都可能成为基于能量的攻击的目标。这项工作通过使用精心设计的多媒体资源适当地请求硬件层编码/解码功能,分析并讨论了新的基于能源的“拒绝服务”攻击的影响和含义,从而引入了异常的电池消耗,从而显着降低了电池消耗缩短了移动智能设备的整体电池寿命。这些攻击不需要物理访问也不需要破坏目标设备,它们利用了可以在正常浏览活动期间正确触发的新HTML5功能。更重要的结果是,数字信号处理器(DSP)提供了可利用的攻击面,在设计过程的早期就应予以考虑。应对措施包括特殊的过滤规则,以防止“无关”的内容到达DSP,或者从更深远的角度来看,在SoC上引入功耗控制器,以监控能耗并发出警报。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号