Article (Périodiques scientifiques)
Vulnerability Analysis and Mitigation of Directed Timing Inference Based Attacks on Time-Triggered Systems
Krüger, Kristin; VOLP, Marcus; Fohler, Gerhard
2018In Leibniz International Proceedings in Informatics, 106, p. 22:1--22:17
Peer reviewed vérifié par ORBi
 

Documents


Texte intégral
LIPIcs-ECRTS-2018-22.pdf
Postprint Éditeur (440.46 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Résumé :
[en] Much effort has been put into improving the predictability of real-time systems, especially in safety-critical environments, which provides designers with a rich set of methods and tools to attest safety in situations with no or a limited number of accidental faults. However, with increasing connectivity of real-time systems and a wide availability of increasingly sophisticated exploits, security and, in particular, the consequences of predictability on security become concerns of equal importance. Time-triggered scheduling with offline constructed tables provides determinism and simplifies timing inference, however, at the same time, time-triggered scheduling creates vulnerabilities by allowing attackers to target their attacks to specific, deterministically scheduled and possibly safety-critical tasks. In this paper, we analyze the severity of these vulnerabilities by assuming successful compromise of a subset of the tasks running in a real-time system and by investigating the attack potential that attackers gain from them. Moreover, we discuss two ways to mitigate direct attacks: slot-level online randomization of schedules, and offline schedule-diversification. We evaluate these mitigation strategies with a real-world case study to show their practicability for mitigating not only accidentally malicious behavior, but also malicious behavior triggered by attackers on purpose.
Disciplines :
Sciences informatiques
Auteur, co-auteur :
Krüger, Kristin;  Technische Universität Kaiserslautern
VOLP, Marcus  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Fohler, Gerhard;  Technische Universität Kaiserslautern
Co-auteurs externes :
yes
Langue du document :
Anglais
Titre :
Vulnerability Analysis and Mitigation of Directed Timing Inference Based Attacks on Time-Triggered Systems
Date de publication/diffusion :
juin 2018
Titre du périodique :
Leibniz International Proceedings in Informatics
ISSN :
1868-8969
Maison d'édition :
Schloss Dagstuhl--Leibniz-Zentrum fuer Informatik, Dagstuhl, Allemagne
Volume/Tome :
106
Pagination :
22:1--22:17
Peer reviewed :
Peer reviewed vérifié par ORBi
Focus Area :
Security, Reliability and Trust
Disponible sur ORBilu :
depuis le 18 décembre 2018

Statistiques


Nombre de vues
423 (dont 10 Unilu)
Nombre de téléchargements
264 (dont 3 Unilu)

citations Scopus®
 
22
citations Scopus®
sans auto-citations
22
citations OpenAlex
 
27

Bibliographie


Publications similaires



Contacter ORBilu