Skip to main navigation Skip to search Skip to main content

CEFI: Command Execution Flow Integrity for Embedded Devices

Research output: Chapter in Book / Report / Conference proceedingConference contributionAcademicpeer-review

96 Downloads (Pure)

Abstract

As embedded devices are widely used in increasingly complex
settings (e.g., smart homes and industrial control systems), one device
is usually connected with multiple entities, such as mobile apps and the
cloud. Recent research has shown that privilege separation vulnerabilities,
which allow violations of authority between different entities, are
occuring in IoT systems. Because such vulnerabilities can be exploited
without violating static control flow and data flow, existing CFI and
DFI solutions cannot prevent them. We present CEFI , the first method
to enforce integrity of command execution on embedded devices after
deployment. CEFI provides fine-grained Command Execution Flow Integrity
by preventing external commands from being executed on control
flow paths belonging to interaction channels that are not authorized to
perform them. Using minimal manual annotations as a starting point,
CEFI statically determined the legal path set (from the start to the
end point) and instruments the program to verify the legitimacy of the
command execution at runtime by checking whether the calling context
is consistent between the runtime executed path and statically obtained
legal path set. We evaluate our prototype with five real-world firmware
samples, and show that CEFI has an average performance overhead of
just 0.18%, an average memory overhead of 0.19%, and that CEFI can
effectively protect embedded devices against attacks on privilege separation
vulnerabilities even if they do not violate control flow.
Original languageEnglish
Title of host publicationDetection of Intrusions and Malware, and Vulnerability Assessment
Subtitle of host publication20th International Conference, DIMVA 2023, Hamburg, Germany, July 12–14, 2023, Proceedings
EditorsDaniel Gruss, Federico Maggi, Mathias Fischer, Michele Carminati
PublisherSpringer Nature
Pages235-255
Number of pages21
ISBN (Electronic)9783031355042
ISBN (Print)9783031355035
DOIs
Publication statusPublished - 2023

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume13959 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Funding

Acknowledgements. We thank our shepherd Roland YAP Hock Chuan and anonymous reviewers for their valuable feedback. This work was supported by the National Natural Science Foundation of China (U1836210), the Key Research and Development Science and Technology of Hainan Province (GHYF2022010), the National Natural Science Foundation of China (No.62202188), and the National Key R&D Program of China (No.2022YFB31033400). Meanwhile, this work was partly done at VU Amsterdam. We thank the support provided by the China Scholarship Council (CSC) and the VUSec Group at VU Amsterdam. Acknowledgments. We would like to thank the anonymous reviewers and the shepherd Moritz Lipp for their very helpful comments and feedback during revision, which have significantly improved the quality and clarity of the work. This research was partially supported by NSF award 2207202. Any opinions, findings, and conclusions or recommendations in this paper are those of the authors and do not necessarily reflect the views of the NSF. Acknowledgments. Code to collect power consumption traces is based on Gras et al. [8]. This work has been partly funded by the ANR-19-CE39-0007 MIAOUS. Experiments presented in this paper were carried out using the Grid’5000 testbed, supported by a scientific interest group hosted by Inria and including CNRS, RENATER and several Universities as well as other organizations (see https://www.grid5000.fr). Acknowledgements. This material is based upon work supported by the National Science Foundation under Grant No. 1814402 and 1814234. Acknowledgements. We thank the reviewers and our shepherd for their helpful comments and suggestions. This work has been supported by ERDF through the EMSIK project and by BMBF through the PeT-HMR project. Acknowledgements. We thank the library maintainers for the smooth disclosure process, and the reviewers and our shepherd for their helpful comments and suggestions. This work has been supported by DFG under grants 427774779 and 439797619, and by BMBF through projects ENCOPIA and PeT-HMR. reviewers for their valuable comments that improved the quality of the paper. We acknowledge the support of the Natural Sciences and Engineering Research Council of Canada (NSERC), funding reference number RGPIN-2018-05919.

FundersFunder number
ANR-19-CE39-0007 MIAOUS
Key Research and Development Science and Technology of Hainan ProvinceGHYF2022010, 62202188
VUSec Group at VU Amsterdam
National Science Foundation1814234, 2207202, 1814402
Natural Sciences and Engineering Research Council of CanadaRGPIN-2018-05919
Deutsche Forschungsgemeinschaft427774779, 439797619
National Natural Science Foundation of ChinaU1836210
Bundesministerium für Bildung und Forschung
China Scholarship Council
European Regional Development Fund
National Key Research and Development Program of China2022YFB31033400

    Fingerprint

    Dive into the research topics of 'CEFI: Command Execution Flow Integrity for Embedded Devices'. Together they form a unique fingerprint.

    Cite this