Munir Geden

dblp:228/3960 · DBLP profile ↗
← Back
5ranked-venue papers
4as first author
3since 2021 · last 2023
0000-0001-6086-0772ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2023 ORC: Increasing Cloud Memory Density via Object Reuse with Capabilities
Vasily A. Sartakov, Lluís Vilanova, Munir Geden, David M. Eyers, Takahiro Shinagawa, Peter R. Pietzuch
OSDI3
2023 RegGuard: Leveraging CPU registers for mitigation of control- and data-oriented attacks
abstract
CPU registers are small discrete storage units that are used to store temporary data and instructions within the CPU. Registers are not addressable in the same way memory is, which makes them immune to memory attacks and manipulation by other means. In this paper, we take advantage of this to protect critical program data with integrity guarantees that cover register spills. This protection effectively addresses control- and data-oriented attacks targeting the stack, even by adversaries with the full knowledge of program memory. Our solution RegGuard is a software-based mitigation technique that uses existing CPU registers and cryptographic primitives to protect critical variables with hardware-level assurance. Unlike conventional register allocation methods, RegGuard prioritises the security significance of a register candidate over its expected performance gain. Our scheme also deals effectively with saved registers to the stack, i.e., when the compiler frees registers to make room for the variables of a new call. With RegGuard, register values saved to the stack are protected, including strong adversaries with arbitrary read and write access capabilities. While our primary design focus is on security, performance is important for a scheme to be adopted in practice. RegGuard is still benefiting from the performance gain normally associated with register allocations and provides practical protection. Despite being adaptable to different CPU architectures, we showcase the performance of RegGuard using different benchmark programs and the C library on the ARM64 architecture as a proof-of-concept.
Munir Geden, Kasper Bonne Rasmussen
Comput. Secur.1
2023 Hardware-assisted remote attestation design for critical embedded systems
abstract
Abstract Remote attestation, as a challenge‐response protocol, enables a trusted entity, called verifier , to ask a potentially infected device, called prover , to provide integrity assurance about its internal state. Remote attestation is becoming increasingly vital for embedded systems that serve in many critical domains, as part of health, military, transportation and industry services, but still lack the most security features available to high‐end systems. In most attestation techniques, the prover provides a cryptographic checksum of its static memory contents, that is, code segments, to the verifier when requested to demonstrate that the device is loaded with the right software. However, those measurements are subject to two limitations. First, they cannot guarantee that the prover has always had legitimate software in the memory prior to attestation. This is because occasional measurements, triggered by the verifier, still leave the device vulnerable to the compromise between two attestation windows as a time‐of‐check‐to‐time‐of‐use (TOCTOU) problem. Second, including dynamic memory regions in the checksum calculation is not helpful in practice, since the verifier typically does not know what those regions should contain or which checksums should be accepted as valid. Hence, many attack scenarios residing in those dynamic regions (e.g. stack) would also go unnoticed. To reveal attack scenarios exploiting the memory regions and time windows left unattested, we propose an attestation scheme that can continuously monitor both static and dynamic memory regions with better spatial and temporal attestation coverage. Our monitoring mechanism is designed to be performed in real time using a novel hardware security module (HSM) connected to the prover's system bus. The proposed HSM monitors not only the integrity of the code on the prover but also its execution by checking the compliance of the bits seen on the bus according to a runtime integrity model (RIM) of the prover's software. Therefore, our attestation scheme is capable of reporting scenarios that violate both the (static) code and (dynamic) runtime integrity since the deployment time.
Munir Geden, Kasper Bonne Rasmussen
IET Inf. Secur.1
2020 TRUVIN: Lightweight Detection of Data-Oriented Attacks Through Trusted Value Integrity
abstract
Data-oriented attacks, where the adversary corrupts critical program data in memory, remain one of the most challenging security threats to address. Because the attacker does not touch any code or code pointers, data-oriented attacks are able to circumvent common defence strategies such as data execution prevention or control-flow protection. Dataflow integrity (DFI) techniques can mitigate these attacks by detecting corruption of any program data. However, due to high performance costs, these techniques are not widely adopted in practice. This paper presents TRUVIN, a lightweight scheme that addresses data-oriented attacks by focusing on only those variables which are crucial to the integrity assurance. Instead of checking every memory operation, TRUVIN selectively instruments program data originating from only trusted agents (e.g., the programmer), as they are considered critical to the runtime integrity. Our scheme analyses the program at compile time, and generates instrumentation only for the necessary operations. TRUVIN reduces the performance cost by a factor of 4.3 on average with 28% overhead compared to full instrumentation (121%), while retaining the security guarantees.
Munir Geden, Kasper Bonne Rasmussen
TrustCom1
2019 Hardware-assisted Remote Runtime Attestation for Critical Embedded Systems
abstract
Remote attestation, as a challenge-response protocol, enables a trusted entity, called verifier, to ask for an untrusted device, called prover, to provide assurance about its internal integrity. Due to its strong guarantees, remote attestation is becoming increasingly popular for critical embedded systems which can be used for medical, military or industrial control purposes. Previous proposals, which used checksums on static code regions to assure the load-time integrity, miss the runtime attacks that affect only dynamic memory regions. To address these attacks, this paper proposes a new scheme that attests the runtime integrity according to the control and data features of the program. The runtime check can be performed in real time with the help of a novel hardware security module (HSM) design which is connected to the prover's system bus. Proposed HSM detects runtime issues by checking compliance of the bits seen on the address and data bus with the static model loaded into its memory. Our attestation scheme is capable of reporting sophisticated runtime attacks such as code-reuse and non-control data attacks.
Munir Geden, Kasper Bonne Rasmussen
PST1