Bouncer: static program analysis in hardware
Joseph McMahan,Michael Christensen,Kyle Dewey,Ben Hardekopf,Timothy Sherwood +4 more
- 22 Jun 2019
- pp 711-722
TL;DR: This work explores an experimental new embedded system that uses special-purpose hardware for static analysis that prevents all program binaries with memory errors, invalid control flow, and several other undesirable properties from ever being loaded onto the device.
read more
Abstract: When discussing safety and security for embedded systems, we typically divide the world into software checks (which are either static or dynamic) or hardware checks (which are dynamic). As others have pointed out, hardware checks offer more than just efficiency. They are intrinsic to the device's functionality and thus are live from power-up; they require little to no dependency on other software functioning correctly, and due to the fact they are wired directly into the operation of the system, are difficult or impossible to bypass. We explore an experimental new embedded system that uses special-purpose hardware for static analysis that prevents all program binaries with memory errors, invalid control flow, and several other undesirable properties from ever being loaded onto the device. Static analysis often requires whole-binary-level, rather than instruction-level, examination. We show that a carefully constructed hardware state machine, using available scratch-pad memory, is capable of efficiently checking functional binaries in a streaming and verifiably non-bypassable way directly in hardware as they are loaded into the embedded program store. The resulting system is surprisingly small (taking no more than .0079 mm2), efficient (capable of checking binaries at an average throughput of around 60 cycles per instruction), and yet guarantees execution free from many of the fragile behaviors that result in security and safety concerns. We believe this is the first time any static analysis has been implemented at the hardware level and opens the door to more complex hardware-checked properties.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
•Dissertation
A type-preserving compiler from system f to typed assembly language
Louis-Julien Guillemette
- 01 Jan 2009
TL;DR: This thesis presents a compiler from a polymorphic higher-order functional language to typed assembly language, whose main property is that type preservation is verified statically, through type annotations on the compiler’s code.
42
C2S: translating natural language comments to formal program specifications
Juan Zhai,Yu Shi,Minxue Pan,Guian Zhou,Yongxiang Liu,Chunrong Fang,Shiqing Ma,Lin Tan,Xiangyu Zhang +8 more
- 08 Nov 2020
TL;DR: A tool to automate the specification synthesis task by translating natural language comments into formal program specifications guided by specification syntax and the context of the target method, substantially outperforming the state-of-the-art.
41
CHEx86: context-sensitive enforcement of memory safety via microcode-enabled capabilities
Rasool Sharifi,Ashish Venkat +1 more
- 30 May 2020
TL;DR: This work introduces the CHEx86 processor architecture for securing applications, including legacy binaries, against a wide array of security exploits that target temporal and spatial memory safety vulnerabilities by instrumenting the code at the microcode-level, completely under thehood, with only limited access to source-level symbol information.
33
The ZARF Architecture for Recursive Functions
Joseph McMahan
- 01 Jan 2019
TL;DR: This work proposes an implementation and provides an evaluation of a device, the Zarf Architecture for Recursive Functions (Zarf), provid-ing a interface of reduced semantic complexity at the ISA level, giving designers a platformenable to reasoning and static analysis.
2
A framework for static analysis and verification of low-level RTOS code
Vignesh Manjunath,Marcel Baunach +1 more
TL;DR: This paper proposes a framework for static analysis and verification of low-level RTOS code, leveraging WCET analysis to ensure correctness against hardware effects and timing, demonstrated on AUTOSAR and FreeRTOS with AURIX TriCore architecture.
References
Z3: an efficient SMT solver
Leonardo de Moura,Nikolaj Bjørner +1 more
- 29 Mar 2008
TL;DR: Z3 is a new and efficient SMT Solver freely available from Microsoft Research that is used in various software verification and analysis applications.
8.2K
MiBench: A free, commercially representative embedded benchmark suite
Matthew R. Guthaus,Jeff Ringenberg,Daniel J. Ernst,Todd Austin,Trevor Mudge,Richard B. Brown +5 more
- 02 Dec 2001
TL;DR: A new version of SimpleScalar that has been adapted to the ARM instruction set is used to characterize the performance of the benchmarks using configurations similar to current and next generation embedded processors.
3.7K
SoftBound: highly compatible and complete spatial memory safety for c
Santosh Nagarakatte,Jianzhou Zhao,Milo M. K. Martin,Steve Zdancewic +3 more
- 15 Jun 2009
TL;DR: Inspired by HardBound, a previously proposed hardware-assisted approach, SoftBound similarly records base and bound information for every pointer as disjoint metadata, which enables SoftBound to provide spatial safety without requiring changes to C source code.
Return-Oriented Programming: Systems, Languages, and Applications
Ryan Glenn Roemer,Erik Buchanan,Hovav Shacham,Stefan Savage +3 more
- 01 Mar 2012
TL;DR: This work presents a high-level, general-purpose language for describing return-oriented exploits and a compiler that translates it to gadgets, and constructs a Turing-complete set of building blocks called gadgets using the standard C libraries of two very different architectures.
When Firmware Modifications Attack: A Case Study of Embedded Exploitation
Ang Cui,Michael Costello,Salvatore J. Stolfo +2 more
- 01 Jan 2013
TL;DR: This paper presents a case study of the HP-RFU (Remote Firmware Update) LaserJet printer firmware modification vulnerability, which allows arbitrary injection of malware into the printer’s firmware via standard printed documents.