跳到主要导航 跳到搜索 跳到主要内容

RapidPatch: Firmware Hotpatching for Real-Time Embedded Devices

  • Yi He
  • , Zhenhua Zou
  • , Kun Sun
  • , Zhuotao Liu
  • , Ke Xu
  • , Qian Wang
  • , Chao Shen
  • , Zhi Wang
  • , Qi Li
  • Tsinghua University
  • George Mason University
  • Wuhan University
  • Florida State University

科研成果: 书/报告/会议事项章节会议稿件同行评审

53 引用 (Scopus)

摘要

Nowadays real-time embedded devices are becoming one main target of cyber attacks. A huge number of embedded devices equipped with outdated firmware are subject to various vulnerabilities, but they cannot be timely patched due to two main reasons. First, it is difficult for vendors who have various types of fragmented devices to generate patches for each type of device. Second, it is challenging to deploy patches on many embedded devices without restarting or halting real-time tasks, hindering the patch installation on devices (e.g., industrial control devices) that have high availability requirements. In this paper, we present RapidPatch, a new hotpatching framework to facilitate patch propagation by installing generic patches without disrupting other tasks running on heterogeneous embedded devices. RapidPatch allows RTOS developers to directly release common patches for all downstream devices so that device maintainers can easily generate device-specific patches for different firmware. We utilize eBPF virtual machines to execute patches on resource-constrained embedded devices and develop three hotpatching strategies to support hotpatching for all major microcontroller (MCU) architectures. In particular, we propose two types of eBPF patches for different types of vulnerabilities and develop an eBPF patch verifier to ensure patch safety. We evaluate RapidPatch with major CVEs on four major RTOSes running on different embedded devices. We find that over 90% vulnerabilities can be hotpatched via RapidPatch. Our system can work on devices with 64 KB or more memory and 64 MHz MCU frequency. The average patch delay is less than 8 µs and the overall latency overhead is less than 0.6%.

源语言英语
主期刊名Proceedings of the 31st USENIX Security Symposium, USENIX Security 2022
出版商USENIX Association
2225-2242
页数18
ISBN(电子版)9781939133311
出版状态已出版 - 2022
活动31st USENIX Security Symposium, USENIX Security 2022 - Boston, 美国
期限: 10 8月 202212 8月 2022

丛书

姓名Proceedings of the 31st USENIX Security Symposium, Security 2022

会议

会议31st USENIX Security Symposium, USENIX Security 2022
国家/地区美国
Boston
时期10/08/2212/08/22

学术指纹

探究 'RapidPatch: Firmware Hotpatching for Real-Time Embedded Devices' 的科研主题。它们共同构成独一无二的学术指纹。

引用此