Logo image
Enforcing Full-Stack Memory-Safety in Cyber-Physical Systems
Conference proceeding   Peer reviewed

Enforcing Full-Stack Memory-Safety in Cyber-Physical Systems

Eyasu Getahun Chekole, Sudipta Chattopadhyay, Martin Ochoa and Guo Huaqun
ENGINEERING SECURE SOFTWARE AND SYSTEMS, ESSOS 2018, Vol.10953, pp.9-26
Lecture Notes in Computer Science
01/01/2018

Abstract

Computer Science Computer Science, Information Systems Computer Science, Software Engineering Science & Technology Technology
Memory-safety attacks are one of the most critical threats against Cyber-Physical Systems (CPS). As opposed to mainstream systems, CPS often impose stringent timing constraints. Given such timing constraints, how can we protect CPS from memory-safety attacks? In this paper, we propose a full-stack memory-safety attack detection method to address this challenge. We also quantify the notion of tolerability of memory-safety overheads (MSO) in terms of the expected real-time constraints of a typical CPS. We implemented and evaluated our proposed solution on a real-world Secure Water Treatment (SWaT) testbed. Concretely, we show that our proposed solution incurs a memory-safety overhead of 419.91 mu s, which is tolerable for the real-time constraints imposed by the SWaT system. Additionally, We also discuss how different parameters of a typical CPS will impact the execution time of the CPS computational logic and memory safety overhead.

Metrics

1 Record Views

Details

Logo image