DocumentCode :
1452261
Title :
Self-Healing Control Flow Protection in Sensor Applications
Author :
Ferguson, Christopher ; Gu, Qijun
Author_Institution :
Network Support Syst., AT&T Wi-Fi Services, Austin, TX, USA
Volume :
8
Issue :
4
fYear :
2011
Firstpage :
602
Lastpage :
616
Abstract :
Since sensors do not have a sophisticated hardware architecture or an operating system to manage code for safety, attacks injecting code to exploit memory-related vulnerabilities can present threats to sensor applications. In a sensor´s simple memory architecture, injected code can alter the control flow of a sensor application to either misuse existing routines or download other malicious code to achieve attacks. To protect the control flow, this paper proposes a self-healing scheme that can stop attacks from exploiting the control flow and then recover sensor applications to normal operations with minimum overhead. The self-healing scheme embeds diversified protection code at particular locations to enforce access control in code memory. Both the access control code and the recovery code are designed to be resilient to control flow attacks that attempt to evade the protection. Furthermore, the self-healing scheme directly processes application code at the machine instruction level, instead of performing control or data analysis on source code. The implementation and evaluation show that the self-healing scheme is lightweight in protecting sensor applications.
Keywords :
authorisation; fault tolerant computing; memory architecture; access control; code memory; data analysis; diversified protection code; machine instruction level; memory architecture; memory-related vulnerabilities; self-healing control flow protection; self-healing scheme; sensor applications; Access control; Computers; Kernel; Memory management; Registers; Sensor application; TinyOS; access control; control flow; self healing; software security.;
fLanguage :
English
Journal_Title :
Dependable and Secure Computing, IEEE Transactions on
Publisher :
ieee
ISSN :
1545-5971
Type :
jour
DOI :
10.1109/TDSC.2011.15
Filename :
5714700
Link To Document :
بازگشت