估计员
计算机科学
子程序
国家(计算机科学)
航程(航空)
过程(计算)
趋同(经济学)
控制理论(社会学)
LTI系统理论
可见的
收敛速度
微控制器
控制(管理)
分布式计算
控制工程
线性系统
算法
计算机硬件
数学
人工智能
工程类
统计
操作系统
量子力学
物理
数学分析
频道(广播)
经济
计算机网络
经济增长
航空航天工程
作者
Dong-Liang Fang,Anni Peng,Le Guan,Erik van der Kouwe,Klaus von Gleissenthall,Wenwen Wang,Yuqing Zhang,Limin Sun
标识
DOI:10.1109/tdsc.2024.3399068
摘要
Deeply embedded devices powered by microcontrollers are widely deployed. To protect them from exploitation, many lightweight defense mechanisms, such as control flow integrity, have been proposed. However, these defenses cannot provide data integrity—a security property of particular interest in mission-critical tasks. Conversely, existing defenses that provide data integrity are too expensive to deploy in the resourceconstrained context of deeply embedded devices. In this paper, we propose InvisiGuard, a hardware-assisted, low overhead approach for data integrity. InvisiGuard leverages data watchpoints—a commonly available debug feature on microcontrollers—to automatically intercept write operations to critical variables. InvisiGuard then checks the legitimacy of the write instruction against an allowlist stored in a trusted execution environment (e.g., ARM
TrustZone-M). By relying on the hardware to automatically intercept potentially dangerous instructions, InvisiGuard avoids heavy code instrumentation, as required by traditional solutions,
making it suitable for resource-constrained microcontroller devices.
We have implemented InvisiGuard on an ARM Cortex-M based development board and evaluated it with seven realworld firmware samples. Our experiments show that InvisiGuard reduces the runtime overhead by 56.99% and memory overhead by 77.37% compared with state of the art.
科研通智能强力驱动
Strongly Powered by AbleSci AI