首页> 外文OA文献 >Code injection attacks on harvard-architecture devices
【2h】

Code injection attacks on harvard-architecture devices

机译:代码注入攻击哈佛架构设备

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Harvard architecture CPU design is common in the embedded world. Examples ofHarvard-based architecture devices are the Mica family of wireless sensors.Mica motes have limited memory and can process only very small packets.Stack-based buffer overflow techniques that inject code into the stack and thenexecute it are therefore not applicable. It has been a common belief that codeinjection is impossible on Harvard architectures. This paper presents a remotecode injection attack for Mica sensors. We show how to exploit programvulnerabilities to permanently inject any piece of code into the program memoryof an Atmel AVR-based sensor. To our knowledge, this is the first result thatpresents a code injection technique for such devices. Previous work onlysucceeded in injecting data or performing transient attacks. Injectingpermanent code is more powerful since the attacker can gain full control of thetarget sensor. We also show that this attack can be used to inject a worm thatcan propagate through the wireless sensor network and possibly create a sensorbotnet. Our attack combines different techniques such as return orientedprogramming and fake stack injection. We present implementation details andsuggest some counter-measures.
机译:哈佛架构的CPU设计在嵌入式世界中很普遍。基于哈佛的体系结构设备的示例是Mica系列无线传感器。Mica节点的内存有限,只能处理非常小的数据包。因此,基于堆栈的缓冲区溢出技术无法将代码注入堆栈,然后执行堆栈。人们普遍认为,在哈佛架构上不可能进行代码注入。本文提出了针对云母传感器的远程代码注入攻击。我们展示了如何利用程序漏洞将任何代码永久地注入基于Atmel AVR的传感器的程序存储器中。据我们所知,这是代表这种设备的代码注入技术的第一个结果。先前的工作仅在注入数据或执行瞬时攻击中成功完成。注入永久代码功能更强大,因为攻击者可以完全控制目标传感器。我们还表明,这种攻击可以用来注入蠕虫,该蠕虫可以通过无线传感器网络传播并可能创建一个sensorbotnet。我们的攻击结合了多种技术,例如面向返回的编程和伪堆栈注入。我们介绍了实施细节,并提出了一些对策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号