Enforcing Full-Stack Memory-Safety in Cyber-Physical Systems

被引:3
作者
Chekole, Eyasu Getahun [1 ,2 ]
Chattopadhyay, Sudipta [1 ]
Ochoa, Martin [1 ,3 ]
Guo Huaqun [2 ]
机构
[1] Singapore Univ Technol & Design, Singapore, Singapore
[2] I2R, Singapore, Singapore
[3] Univ Rosario, Dept Appl Math & Comp Sci, Bogota, Colombia
来源
ENGINEERING SECURE SOFTWARE AND SYSTEMS, ESSOS 2018 | 2018年 / 10953卷
关键词
D O I
10.1007/978-3-319-94496-8_2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Memory-safety attacks are one of the most critical threats against Cyber-Physical Systems (CPS). As opposed to mainstream systems, CPS often impose stringent timing constraints. Given such timing constraints, how can we protect CPS from memory-safety attacks? In this paper, we propose a full-stack memory-safety attack detection method to address this challenge. We also quantify the notion of tolerability of memory-safety overheads (MSO) in terms of the expected real-time constraints of a typical CPS. We implemented and evaluated our proposed solution on a real-world Secure Water Treatment (SWaT) testbed. Concretely, we show that our proposed solution incurs a memory-safety overhead of 419.91 mu s, which is tolerable for the real-time constraints imposed by the SWaT system. Additionally, We also discuss how different parameters of a typical CPS will impact the execution time of the CPS computational logic and memory safety overhead.
引用
收藏
页码:9 / 26
页数:18
相关论文
共 31 条
[1]  
Abadi M., 2005, P 12 ACM C COMP COMM, P340, DOI 10.1145/1102120.1102165.2
[2]  
Ahmed C. M., 2016, SCSP W 2016
[3]  
[Anonymous], 2018, LIST KERNEL BUGS DET
[4]  
Berger E. D, 2006, PLDI 2006
[5]  
Bruening D, 2011, CGO 2011
[6]   Enforcing Memory Safety in Cyber-Physical Systems [J].
Chekole, Eyasu Getahun ;
Castellanos, John Henry ;
Ochoa, Martin ;
Yau, David K. Y. .
COMPUTER SECURITY, 2017, 2018, 10683 :127-144
[7]  
Cooprider N, 2007, SENSYS'07: PROCEEDINGS OF THE 5TH ACM CONFERENCE ON EMBEDDED NETWORKED SENSOR SYSTEMS, P205
[8]  
Eigler F., 2003, GCC DEV SUMM
[9]  
Gay D., 2003, PLDI 2003
[10]  
Hu H., 2016, SP 2016