Gedare Bloom

dblp:76/7561 · DBLP profile ↗
← Back
38ranked-venue papers
5as first author
24since 2021 · last 2026
0000-0002-5677-7092ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 12 · 2 first-author · 8 since 2021Systems, architecture and hardware · 9 · 5 since 2021Security and privacy · 5 · 2 first-author · 2 since 2021Computer networks · 2 · 2 since 2021Software engineering, systems software and programming languages · 2
YearPublicationVenuePosition
2026 Game of Nodes: Securing the SCADA Realm through Optimized Network Sensor Placement
abstract
Supervisory Control and Data Acquisition (SCADA) systems are critical to the operation of industrial and commercial infrastructure but are increasingly exposed to cyber threats due to legacy design, limited operational flexibility, and the need for continuous availability. Traditional IT security solutions often prove unsuitable in these environments, as they can introduce latency, conflict with system operation, and fall short of the real-time performance requirements of mission-critical systems. Passive monitoring tools—such as network sensors—offer a safer alternative by enabling traffic visibility without disrupting safety or mission-critical functionality. In industrial settings, where operational conditions are both resource-constrained and high-risk, strategic sensor placement becomes crucial.This paper presents a graph-theoretic framework that lever-ages combinatorial centrality metrics to identify key nodes for network sensor deployment, with the goal of maximizing traffic visibility and enhancing threat detection. By replacing heuristic or subjective placement decisions with a data-driven, network-science approach, the framework supports improved operational resilience and situational awareness. Simulation-based experiments demonstrate that this framework, when applied large scale to the entire network, outperforms both random and heuristically informed sensor placement strategies in detection of anomalies while remaining effective under dynamic conditions in large, distributed SCADA networks.
Douglas Healy, Karl M. Olson, Gedare Bloom
CCNC3
2026 Ciao: Cross-architecture IoT Malware Family Classification with Code Reuse
abstract
Classifying malware variants into their respective families is a key challenge in malware analysis. This task is especially difficult with IoT malware because of code reuse and a variety of instruction set architectures (ISAs). Adversaries often reuse code across malware families through the same library functions, leaked source code, or known exploits. This practice makes it difficult for traditional Machine Learning (ML) classifiers to be reliable for malware classification. Further, IoT malware targets diverse instruction set architectures (ISAs), where differences in opcodes and registers create variations that hinder effective malware analysis. We present Ciao, a tool that uses an architecture-agnostic instruction representation and graph representation learning that captures family-specific logic even under heavy code reuse. Our evaluation of Ciao on a dataset of 9,954 IoT malware samples achieves an accuracy of 98.50%, a macro precision of 99.01%, and a macro recall of 98.94% in malware classification under code reuse, which outperforms existing techniques. Furthermore, in cross-architecture classification, where samples from one architecture are underrepresented, Ciao outperforms a model that uses architecture-specific instruction representation.
Minhajul Alam Rahat, Vijay Banerjee, Gedare Bloom, Yanyan Zhuang
CCNC3
2026 Schedule-Based Attack Against TSN TAS with Frame Preemption
abstract
Time-Sensitive Networking (TSN) achieves deterministic communication using mechanisms like Time-Aware Shaping, which manages the timing of network traffic streams using a Gate Control List (GCL). The GCL operates according to a cyclic schedule by opening and closing gates for priority (egress) queues in out-bound ports. However, the cyclic schedule in the GCL introduces potential security vulnerabilities to schedule-based attacks. This type of attack exploits TSN’s deterministic schedules to manipulate traffic flow and can impact availability and safety. Traditional intrusion detection systems (IDS) are commonly employed in TSN to detect malicious activities by monitoring traffic patterns and bandwidth usage. However, schedule-based attacks can align malicious packets with legitimate traffic, making the attack more stealthy and harder to detect by rate-based IDS. This paper presents a novel schedule-based attack that synchronizes malicious traffic to exploit predictability in TSN’s GCL schedule. This attack causes an adversarial blocking in which low-priority traffic delays higher-priority traffic without being detected using a rate-based IDS. We demonstrate the feasibility and impact of this schedule-based attack on TSN with off-the-shelf hardware.
Omolade Ikumapayi, Vijay Banerjee, Sena Hounsinou, Gedare Bloom
ECRTS4
2026 On Evading Randomization-Based Defense in Hierarchical Real-Time Systems
abstract
Security for real-time systems is increasingly important with the growth of connected real-time systems in safety-critical domains such as automotive, medical, and avionics. A crucial aspect of securing such systems is to understand the attacks that the current techniques cannot effectively safeguard against. Especially relevant are vulnerabilities of real-time systems arising from their rigid temporal guarantees and attacks that exploit such vulnerabilities. Randomization-based defense techniques can reduce side-channel inference, but such techniques are limited due to the strict timing bounds of real-time systems. In this article, we design and analyze NosyNeighbor , an inter-partition side-channel attack that exploits the timing guarantees of real-time systems to infer the timing parameters of a safety-critical task in a hierarchical system. Using an adaptive technique, NosyNeighbor can improve its inference over time and evade randomization-based defense. Experimental results show that NosyNeighbor can infer victim task execution with a precision of roughly 73% under normal system load, and with a recall of about 35% using multiple malicious tasks across partitions. NosyNeighbor is also effective under the common attack model with two malicious tasks in the system, with a precision of 64%.
Vijay Banerjee, Sena Hounsinou, Yanyan Zhuang, Monowar Hasan, Gedare Bloom
ACM Trans. Cyber Phys. Syst.5
2026 CD-SAC: Constant Distance With Speed Adjustment in Curves for Non-Column Vehicle Platoon Control
abstract
Unmanned ground vehicle platoons are not constrained to travel in columns on well-marked roads. Allowing lateral inter-vehicle spacing creates unique challenges compared with highway driving in restricted column formations. These challenges include the absence of road markings and planned trajectories along with differences in velocity and position keeping while turning. In this paper, we introduce a real-time velocity adjustment based on turning radius for non-column formations that addresses the discrepancy in matching velocities in a turn. Two non-column formations are evaluated over two network topologies with varying connectivity using a two-dimensional scenario which simultaneously invokes an acceleration and a heading change using a dynamic three-degree-of-freedom vehicle model. A velocity adjustment is made in curves where predecessors are laterally offset with the ego vehicle. If the predecessor’s turning radius is smaller (larger), the ego vehicle’s velocity increases (decreases). This novel adjustment is a deviation from the status quo where competing control actions exist between maintaining a constant inter-vehicle spacing and matching velocities in curves. Experimental results using this novel velocity adjustment show a maximum 74% decrease in longitudinal distance error, a maximum 94% decrease in lateral distance error across platoon followers and a significant reduction in standard deviation across platoon members along experimental path trajectories.
Constance Hendrix, Gedare Bloom
IEEE Trans. Intell. Transp. Syst.2
2025 A Systematic Framework for Generative AI-Powered Curriculum Development: Integrating Industry Requirements with Agile Learning
abstract
The dynamic cybersecurity threats in specialized domains like space systems create significant challenges for educational content development. Traditional curriculum development struggles to keep pace with dynamic industry requirements, taking months to develop and requiring large expert teams. This paper introduces a systematic framework that integrates Generative AI (GenAI) with established instructional design principles to rapidly develop domain-specific cybersecurity training. Our framework combines Retrieval Augmented Generation (RAG) with the Analysis, Design, Development, Implementation, and Evaluation (ADDIE) model, enabling requirements-driven curriculum development that translates industry stakeholder interviews and job descriptions directly into comprehensive educational materials. We demonstrate framework feasibility through Space Information Systems Security Officer (ISSO) curriculum development, generating 500+ domainspecific Knowledge, Skills, and Tasks (KSTs), modular lectures, 886 assessment questions, and gamified exercises within hours rather than months. Market research with 33 industry professionals revealed critical gaps in existing training frameworks, with $82 \%$ emphasizing soft skills and $67 \%$ requiring holistic system understanding beyond traditional cybersecurity domains. Our proof-of-concept implementation with 5 completing participants showed promising results with test scores improving from $73.9 \%$ to $92.1 \%$, though larger validation studies are needed. The systematic framework addresses identified gaps in current cybersecurity training approaches while providing a replicable methodology for other rapidly evolving technical domains requiring specialized workforce development.
Jordan Scott, Gedare Bloom, George Bailey
ISNCC2
2025 Work-in-Progress: Vulnerability of TSN TAS with Frame Preemption to Schedule-Based Attack
abstract
Time-Sensitive Networking enables deterministic communication in cyber-physical systems using time-aware shapers governed by Gate Control Lists (GCL). Although this mechanism improves reliability, it also introduces vulnerabilities exploitable through schedule-based attacks. We show that, by analyzing traffic patterns, adversaries can estimate GCL parameters and reconstruct the schedule to inject precisely timed traffic. These injections can cause priority inversions, where low-priority flows delay high-priority traffic, degrading latency and schedulability. Such schedule-based attacks are particularly stealthy as conventional Intrusion Detection Systems (IDS) may fail to detect them. We implement this attack and conduct randomized experiments to evaluate the impact on synthetic workloads and on off-the-shelf hardware.
Omolade Ikumapayi, Vijay Banerjee, Sena Hounsinou, Gedare Bloom
RTSS4
2025 Poster Abstract: Operational Similarity in IoT Malware Development Life Cycle
abstract
Due to hardware limitations and low cost, manufacturers often overlook security in widely deployed IoT devices, making them susceptible to attacks. Malware is one such attack that can cause extensive damage. In this work, we analyze a large corpus of IoT malware to extract features that emerge from the shared development and logistics in the malware development life cycle (MDLC), which we name operational features. We use these features to formulate a novel operational similarity concept for malware families and variants that complements existing code and behavior analysis.
Minhajul Alam Rahat, Vijay Banerjee, Gedare Bloom, Yanyan Zhuang
SenSys3
2024 Platoon Vulnerability due to Network Topology and Targeted Vehicle
abstract
Vehicle platooning is a key application for intelligent transportation systems that brings the joint problem of maintaining safety and security as prioritized requirements. The complex and dynamic electromagnetic environment coupled with sophisticated adversarial threats motivate better understanding of platoon control resilience from traditional faults, disturbances, and attack injects. An open problem for this understanding is the impact that information flow (communication network) topologies have on the attack and defense strategies for vehicular platoons. As the topology changes, vulnerability amongst platoon members and their individual contributions to the overall platoon security also change. This paper evaluates the impact of member-specific targeting informed by topology and demonstrates that targeting one member over another can be advantageous to the attacker. Furthermore, we present a taxonomy to identify topologies by key characteristics as an option for an industry standard.
Constance Hendrix, Gedare Bloom
CCNC2
2024 MCFICS: Model-based Coverage-guided Fuzzing for Industrial Control System Protocol Implementations
abstract
Industrial control system (ICS) protocols face the threat of adversaries launching cyber-physical attacks against protocol endpoints. Vulnerability discovery approaches such as fuzzing can be effective at reducing the risk of such threats. In this paper, we present MCFICS, a coverage-guided greybox fuzzing framework that uses (1) active automata learning for stochastic reactive systems to infer the state machine of a stateful ICS protocol server implementation, and (2) guided fuzzing to explore the state space using this learned state machine. During fuzzing, new input sequences that increase code coverage are used to improve the state space exploration of the ICS protocol implementations. We implemented and tested MCFICS with six example server implementations spanning three widely used ICS protocol implementations. Experimental results show that MCFICS achieves higher branch coverage than the AFLNwe, AFLNet and StateAFL fuzzers by an average (mean of means) of 15.82%, 1.99%, and 37.52%, respectively, with an overall average of 18.44% increased branch coverage. Furthermore, using MCFICS we discovered a new bug in a protocol implementation that we have reported to its upstream maintainer.
Uchenna Ezeobi, Sena Hounsinou, Habeeb Olufowobi, Yanyan Zhuang, Gedare Bloom
IECON5
2024 Resiliency of Vehicle Platoon Network Topologies under Physical Attack
abstract
Vehicle platooning inspires the future of transportation and yet introduces the possibility for physical attacks to disrupt autonomy operations. In this paper, we evaluate platoon resiliency in the presence of such attacks. Our evaluation includes 60 unique combinations of controller, control policy, and topology with an equal weight control schema while attacking specific platoon members. The experimental results show that the targeted vehicle, network topology, control policy, and controller all influence platoon resiliency with some configurations leading to platoon instability.
Constance Hendrix, Gedare Bloom
IECON2
2024 From Weeping to Wailing: A Transitive Stealthy Bus-Off Attack
abstract
The integration of the Internet of Things (IoT) devices and solutions into passenger vehicles has transformed cars into a complex system with intelligence and a platform for extending information technology possibilities. These devices communicate through in-vehicle networks that use the controller area network (CAN) as a de facto standard for the safety-critical functionality of the vehicles. One creative exploit against CAN is the bus-off attack, which uses the fault tolerance capabilities of the CAN bus to coerce a victim electronic control unit (ECU) into the bus-off state from which it is not allowed to access the bus. As a result, the victim ECU is unable to send or receive messages. The WeepingCAN attack is a stealthy variation of the bus-off attack that reduces its observability and therefore the effectiveness of detection-based mitigation. In this paper, we introduce three software-based improvements that greatly increase both the efficiency and effectiveness of the WeepingCAN attack. First, we introduce a novel zero-phase approach for synchronizing the attack. Second, we discover an alternative approach to disable retransmissions, which is a key capability of WeepingCAN, that allows the attack to be conducted from more ECUs than before. Third, we identify a transitive attack strategy that enables an attacker to target many more ECUs than originally possible. We evaluate our improvements experimentally using a CAN benchmark and find that the zero-phase synchronization improves the attack success rate from 75% to over 90% and the transitive attack strategy enables all the ECUs in the benchmark to be attacked.
Paul Agbaje, Habeeb Olufowobi, Sena Hounsinou, Gedare Bloom
IEEE Trans. Intell. Transp. Syst.4
2023 Work in Progress: Schedulability Analysis of CAN and CAN FD Authentication
abstract
Ensuring the data integrity of messages transmitted over the Controller Area Network (CAN) bus and other vehicular networks is achieved through the implementation of cryptographic authentication protocols. However, these protocols raise concerns about a significant increase in response time due to the restrictions on CAN frame size and bandwidth. This paper presents a comprehensive analysis of the impact on response time of CAN and CAN Flexible Data-rate (CAN FD) messages with the implementation of cryptographic message authentication codes (MACs) and the periodic transmission of these codes. Our evaluation is based on a randomized schedulability experiment to provide insights into the overhead incurred by adding authentication to the frame payloads.
Omolade Ikumapayi, Habeeb Olufowobi, Jeremy Daily, Ivan Cibrario Bertolotti, Gedare Bloom
RTAS6
2023 Sidecar-based Path-aware Security for Microservices
abstract
Microservice architectures decompose web applications into loosely-coupled, distributed components that interact with each other to provide an overall service. While this popular software architecture paradigm has many advantages in development and deployment, it also introduces a wider attack surface that is vulnerable to both internal and external attackers. Potentially malicious third-party services or software packages, as well as increased communication endpoints, introduce a wide array of security concerns. To improve the resiliency of microservice-based applications, many of which store sensitive data, we propose a novel, path-based anomaly detection and access control infrastructure that requires no modifications to existing software. We propose leveraging trusted proxies deployed alongside each service for request inspection, anomaly detection and signed token propagation for end-user path validation. Our approach reduces the trusted computing base away from the microservices to a smaller set of components that allow for less trust and a smaller attack surface.
Catherine Meadows 0002, Sena Hounsinou, Timothy Wood 0001, Gedare Bloom
SACMAT4
2022 The Tragedy of the Miners
abstract
In a network of mining pools that secure Bitcoin-like blockchains, it is known that a self-interested mining pool can dishonestly siphon off another pool’s mining rewards by executing a block withholding (BWH) attack. In this paper, we show that a BWH attack is always unprofitable for an initial startup period which is at least one difficulty retarget interval (approximately 14 days for Bitcoin). Furthermore, we prove that the payback period to recoup this initial startup cost is always at least as long as the initial unprofitable startup interval, and we show numerically that it can be substantially longer. Thus, the decision of whether or not to execute a BWH attack is not a dominant strategy, and the so called Miner’s Dilemma is not in fact a dilemma.
Vijay Banerjee, Ryan Rabinowitz, Mark Stidd, Rory A. Lewis, Philip N. Brown, Gedare Bloom
CCNC6
2022 Shining New Light on Useful Features for Network Intrusion Detection Algorithms
abstract
Network intrusion detection systems (NIDS) today must quickly provide visibility into anomalous behavior on a growing amount of data. Meanwhile different data models have evolved over time, each providing a different set of features to classify attacks. Defenders have limited time to retrain classifiers, while the scale of data and feature mismatch between data models can affect the ability to periodically retrain. Much work has focused on classification accuracy yet feature selection is a key part of machine learning that, when optimized, reduces the training time and can increase accuracy by removing poorly performing features that introduce noise. With a larger feature space, the pursuit of more features is not as valuable as selecting better features. In this paper, we use an ensemble approach of filter methods to rank features followed by a voting technique to select a subset of features. We evaluate our approach using three datasets to show that, across datasets and network topologies, similar features have a trivial effect on classifier accuracy after removal. Our approach identifies poorly performing features to remove in a classifier-agnostic manner that can significantly save time for periodic retraining of production NIDS.
Heather Lawrence, Uchenna Ezeobi, Gedare Bloom, Yanyan Zhuang
CCNC3
2022 Evaluating Feature Robustness for Windows Malware Family Classification
abstract
Machine learning approaches to classify malware by family save analysts valuable time during incident response. A key challenge for these approaches is selecting features that are robust against concept drift, which describes the change in malware over time. In this paper, we evaluate a dynamic feature set based on Windows handles (e.g., files, registry keys) for malware family classification. Specifically, we examine the features' vulnerabilities and evaluate their robustness against concept drift. We curated a novel dataset that simulates the manipulations that attackers may invoke on malware samples. We demonstrate improved robustness to concept drift over traditional API call-based features by training machine learning classifiers on malware collected in the wild, and testing the classifiers against samples that underwent manipulations. Further, we investigate time decay due to concept drift using temporally consistent evaluations that do not assume access to newer information. The evaluation shows that our features are robust against malware obfuscation. Furthermore, we empirically demonstrate how malware labeling conventions (malware type or family) can affect results, and make recommendations for dataset construction.
Adam Duby, Teryl Taylor, Gedare Bloom, Yanyan Zhuang
ICCCN3
2022 Poster: Toward Zero-Trust Path-Aware Access Control
abstract
In this poster, we introduce path-aware risk scores for access control (PARSAC), a novel context-sensitive technique to enrich access requests with risk scoring of the path taken by those requests between the authenticated user and the resources they access. These path-aware risk scores enable another layer of security for traditional access control systems that addresses the need for fine-grained monitoring and enforcement within a zero-trust architecture. We define rules for general functions that can be used to determine risk and instantiate a specific approach to calculate path risk scores. We evaluate our approach with realistic network graphs; PARSAC finds more paths with lower risk when compared with traditional routing algorithms that select the shortest path.
Joshua H. Seaton, Sena Hounsinou, Timothy Wood 0001, Shouhuai Xu, Philip N. Brown, Gedare Bloom
SACMAT6
2022 CUPID: A labeled dataset with Pentesting for evaluation of network intrusion detection
Heather Lawrence, Uchenna Ezeobi, Orly Tauil, Jacob Nosal, Owen Redwood, Yanyan Zhuang, Gedare Bloom
J. Syst. Archit.7
2022 Survey of Interoperability Challenges in the Internet of Vehicles
abstract
The Internet of Vehicles (IoV) is an active area for innovation and an essential tool in achieving smart cities through the integration of vehicles with the Internet of Things (IoT). IoV is a distributed network that aids in handling the data generated by vehicular sensors and vehicle-to-everything communication (V2X), thus enabling novel applications such as autonomous driving and platooning while increasing safety and energy efficiency. In IoV, the sensors and the interdependent devices relay critical information for the efficient implementation of real-time applications in the ecosystem. Despite all these advancements, a vital challenge is establishing smooth communication among interconnected devices, concretely, interoperability in the IoV—a deceptively simple notion that is not yet fully addressed to achieve a fully integrated ecosystem. This is mainly because the networked domains, such as home, grid, and health care, are developed in silos, operating independently with diverse processes and protocols. Hence, seamless exchange of information is yet to be achieved across the ecosystem, hindering the maximization of the full promise of IoV. In this paper, we provide an in-depth analysis of the present state of interoperability and comprehensively survey the challenges in IoV. We present a taxonomy of interoperability approaches, review solutions that prior work have proposed, and provide insights on how to address the current challenges. Finally, we identify open problems that persist and future directions for research.
Paul Agbaje, Afia Anjum, Arkajyoti Mitra, Emmanuel Oseghale, Gedare Bloom, Habeeb Olufowobi
IEEE Trans. Intell. Transp. Syst.5
2021 Strong APA scheduling in a real-time operating system: work-in-progress
abstract
Arbitrary processor affinities are used in multiprocessor systems to specify the processors on which a task can be scheduled. However, affinity constraints can prevent some high priority real-time tasks from being scheduled, while lower priority tasks execute. This paper presents an implementation and evaluation of the Strong Arbitrary Processor Affinity scheduling on a real-time operating system, an approach that not only respects user-defined affinities, but also supports migration of a higher priority task to allow execution of a task limited by affinity constraints. Results show an improvement in response and turnaround times of higher priority tasks.
Richi Dubey, Vijay Banerjee, Sena Hounsinou, Gedare Bloom
EMSOFT4
2021 Work-in-Progress: Enabling Secure Boot for Real-Time Restart-Based Cyber-Physical Systems
abstract
Several cyber-physical systems use real-time restart-based embedded systems with the Simplex architecture to provide safety guarantees against system faults. Some approaches have been developed to protect such systems from security violations too, but none of these approaches can prevent an adversary from modifying the operating system or application code to execute an attack that persists even after a reboot. In this work, we present a secure boot mechanism to restore real-time restart-based embedded systems into a secure computing environment after every restart. We analyze the delay introduced by the proposed security feature and present preliminary results to demonstrate the viability of our approach using an open-source bootloader and real-time operating system.
Sena Hounsinou, Vijay Banerjee, Chunhao Peng, Monowar Hasan, Gedare Bloom
RTSS5
2021 Vulnerability of Controller Area Network to Schedule-Based Attacks
abstract
The secure functioning of automotive systems is vital to the safety of their passengers and other roadway users. One of the critical functions for safety is the controller area network (CAN), which interconnects the safety-critical electronic control units (ECUs) in the majority of ground vehicles. Unfortunately CAN is known to be vulnerable to several attacks. One such attack is the bus-off attack, which can be used to cause a victim ECU to disconnect itself from the CAN bus and, subsequently, for an attacker to masquerade as that ECU. A limitation of the bus-off attack is that it requires the attacker to achieve tight synchronization between the transmission of the victim and the attacker’s injected message. In this paper, we introduce a schedule-based attack framework for the CAN bus-off attack that uses the real-time schedule of the CAN bus to predict more attack opportunities than previously known. We describe a ranking method for an attacker to select and optimize its attack injections with respect to criteria such as attack success rate, bus perturbation, or attack latency. The results show that vulnerabilities of the CAN bus can be enhanced by schedulebased attacks.
Sena Hounsinou, Mark Stidd, Uchenna Ezeobi, Habeeb Olufowobi, Mitra Nasri, Gedare Bloom
RTSS6
2021 Precise Cache Profiling for Studying Radiation Effects
abstract
Increased access to space has led to an increase in the usage of commodity processors in radiation environments. These processors are vulnerable to transient faults such as single event upsets that may cause bit-flips in processor components. Caches in particular are vulnerable due to their relatively large area, yet are often omitted from fault injection testing because many processors do not provide direct access to cache contents and they are often not fully modeled by simulators. The performance benefits of caches make disabling them undesirable, and the presence of error correcting codes is insufficient to correct for increasingly common multiple bit upsets. This work explores building a program’s cache profile by collecting cache usage information at an instruction granularity via commonly available on-chip debugging interfaces. The profile provides a tighter bound than cache utilization for cache vulnerability estimates (50% for several benchmarks). This can be applied to reduce the number of fault injections required to characterize behavior by at least two-thirds for the benchmarks we examine. The profile enables future work in hardware fault injection for caches that avoids the biases of existing techniques.
Robert Gifford, Gedare Bloom, Gabriel Parmer, Rahul Simha
ACM Trans. Embed. Comput. Syst.3
2020 Harmonizing ARINC 653 and Realtime POSIX for Conformance to the FACE Technical Standard
abstract
The avionics industry is converging toward the next generation of software standards produced by The Open Group via the Future Airborne Capability Environment (FACE) consortium and related FACE Technical Standard. The standard combines ARINC 653, a previous avionics standard, with subsets of POSIX 1003.1 that are closely aligned with the POSIX realtime profiles PSE52, PSE53, and PSE54. In this paper, we describe our approach to design, implement, and certify a system with FACE Conformance to the FACE Operating System Segment Safety Base profile. Our approach integrates the ARINC 653-compliant Deos with RTEMS, an open-source real-time operating system (RTOS). Our goal in combining Deos/RTEMS was to achieve certification of FACE Conformance in a low-cost manner by relying on existing, mature software that already provides the majority of the functionality required by the FACE Technical Standard. We reached our goal with under 10,000 source lines of code (SLOC) written to integrate RTEMS into Deos and implement any additional POSIX application programming interfaces (APIs) and tests needed for certification.
Gedare Bloom, Joel Sherrill
ISORC1
2020 Towards Industrial Security Through Real-time Analytics
abstract
Industrial control system (ICS) denotes a system consisting of actuators, control stations, and network that manages processes and functions in an industrial setting. The ICS community faces two major problems to keep pace with the broader trends of Industry 4.0: (1) a data rich, information poor (DRIP) syndrome, and (2) risk of financial and safety harms due to security breaches. In this paper, we propose a private cloud in the loop ICS architecture for real-time analytics that can bridge the gap between low data utilization and security hardening.
Prajjwal Dangal, Gedare Bloom
ISORC2
2019 On the Pitfalls and Vulnerabilities of Schedule Randomization Against Schedule-Based Attacks
abstract
Schedule randomization is one of the recently introduced security defenses against schedule-based attacks, i.e., attacks whose success depends on a particular ordering between the execution window of an attacker and a victim task within the system. It falls into the category of information hiding (as opposed to deterministic isolation-based defenses) and is designed to reduce the attacker's ability to infer the future schedule. This paper aims to investigate the limitations and vulnerabilities of schedule randomization-based defenses in real-time systems. We first provide definitions, categorization, and examples of schedule-based attacks, and then discuss the challenges of employing schedule randomization in real-time systems. Further, we provide a preliminary security test to determine whether a certain timing relation between the attacker and victim tasks will never happen in systems scheduled by a fixed-priority scheduling algorithm. Finally, we compare fixed-priority scheduling against schedule-randomization techniques in terms of the success rate of various schedule-based attacks for both synthetic and real-world applications. Our results show that, in many cases, schedule randomization either has no security benefits or can even increase the success rate of the attacker depending on the priority relation between the attacker and victim tasks.
Mitra Nasri, Thidapat Chantem, Gedare Bloom, Ryan M. Gerdes
RTAS3
2019 Event Notification in CAN-Based Sensor Networks
abstract
Preventive and reactive maintenance require the collection of an ever-increasing amount of information from industrial plants and other complex systems such as those based on robotized cells, a need that can be fulfilled by means of a suitable event notification mechanism. At the same time, timing and delivery reliability requirements in those scenarios are typically less demanding than those in other cases, thus enabling the adoption of best-effort notification approaches. This paper presents, evaluates, and compares some of those approaches, based on either standard Controller Area Network (CAN) messaging or a recently proposed protocol extension called CAN with eXtensible in-frame Reply (CAN XR). In the second case, the combined use of Bloom filters is also envisaged to increase flexibility. Results show that the latter approaches are advantageous in a range of event generation rates and network topologies of practical relevance.
Gedare Bloom, Gianluca Cena, Ivan Cibrario Bertolotti, Nicolas Navet, Adriano Valenzano
IEEE Trans. Ind. Informatics1
2018 The future of IoT security: special session
abstract
The Internet-of-Things (IoT) is a large and complex domain. These systems are often constructed using a very diverse set of hardware, software and protocols. This, combined with the ever increasing number of IoT solutions/services that are rushed to market means that most such systems are rife with security holes. Recent incidents (e.g., the Mirai botnet) further highlight such security issues. With emerging technologies such as blockchain and software-defined networks (SDNs), new security solutions are possible in the IoT domain. In this paper we will explore future trends in IoT security: (a) the use of blockchains in IoT security, (b) data provenance for sensor information, (c) reliable and secure transport mechanisms using SDNs (d) scalable authentication and remote attestation mechanisms for IoT devices and (e) threat modeling and risk/maturity assessment frameworks for the domain.
Sibin Mohan, Mikael Asplund, Gedare Bloom, Ahmad-Reza Sadeghi, Ahmad Ibrahim 0002, Negin Salajageh, Paul Griffioen, Bruno Sinopoli
EMSOFT3
2018 Work-in-Progress: Real-Time Modeling for Intrusion Detection in Automotive Controller Area Network
abstract
Security of vehicular networks has often been an afterthought since they are designed traditionally to be a closed system. An attack could lead to catastrophic effect which may include loss of human life or severe injury to the driver and passengers of the vehicle. In this paper, we propose a novel algorithm to extract the real-time model of the controller area network (CAN) and develop a specification-based intrusion detection system (IDS) using anomaly-based supervised learning with the real-time model as input. We evaluate IDS performance with real CAN logs collected from a sedan car.
Habeeb Olufowobi, Gedare Bloom, Clinton Young, Joseph Zambreno
RTSS2
2017 Work-in-Progress: Reducing Cache Conflicts via Interrupts and BUNDLE Scheduling
abstract
In "BUNDLE: Real-Time Multi-Threaded Scheduling to Reduce Cache Contention" Tessler and Fisher present a positive perspective of instruction caches for hard real-time multithreaded tasks. The thread-aware scheduling algorithm limits the execution of threads to sets of instructions that cannot result in cache conflicts. Identification of these sets result in conflict free regions which are used to identify scheduling groups called bundles in the BUNDLE scheduling algorithm. Placement of a thread in a particular bundle depends on, what the authors call, "anticipating execution". However, they do not define a complete mechanism to anticipate execution. In this work, we propose a method to anticipate execution that modifies cache hardware and introduces a new interrupt raised prior to a cache conflict. This new interrupt is combined with (a slightly modified version of) the BUNDLE scheduling algorithm. The intent is to implement these hardware modifications for ARM on the gem5 simulator with the scheduling algorithm integrated into the RTEMS operating system. The hope is this work serves as further motivation to bring the positive perspective of caches to physical processors and operating systems.
Corey Tessler, Gedare Bloom, Nathan Fisher
RTAS2
2016 SuperGlue: IDL-Based, System-Level Fault Tolerance for Embedded Systems
abstract
As the processor feature sizes shrink, mitigating faults in low level system services has become a critical aspect of dependable system design. In this paper we introduce SuperGlue, an interface description language (IDL) and compiler for recovery from transient faults in a component-based operating system. SuperGlue generates code for interface-driven recovery that uses commodity hardware isolation, micro-rebooting, and interface-directed fault recovery to provide predictable and efficient recovery from faults that impact low-level system services. SuperGlue decreases the amount of recovery code system designers need to implement by an order of magnitude, and replaces it with declarative specifications. We evaluate SuperGlue with a fault injection campaign in low-level system components (e.g., memory mapping manager and scheduler). Additionally, we evaluate the performance of SuperGlue in a web-server application. Results show that SuperGlue improves system reliability with only a small performance degradation of 11.84%.
Jiguo Song, Gedare Bloom, Gabriel Parmer
DSN2
2016 Verifying Nested Lock Priority Inheritance in RTEMS with Java Pathfinder
Saurabh Gadia, Cyrille Artho, Gedare Bloom
ICFEM3
2016 CBufs: efficient, system-wide memory management and sharing
abstract
Modern systems are composed of many different protection domains separating privilege levels, subsystems, users, clients, and software of differing levels of assurance. System-wide memory management must consider not only allocation to single processes, but also efficient sharing of data across protection domains, and the allocation of memory based on the performance of applications that span multiple protection domains. This paper introduces the CBuf system for the global management of virtual and physical memory, including zero-copy sharing between protection domains. We present the design and implementation of both garbage collection techniques to enable efficient sharing, and policies that balance memory between protection domains specifically to satisfy system and application constraints such as quality of service. We show that a CBuf-enabled webserver achieves over a factor of 2.5 throughput speedup while using less processing time than Apache on Linux, and that the system can intentionally control system throughput through intelligent memory allocation.
Yuxin Ren 0001, Gabriel Parmer, Teo Georgiev, Gedare Bloom
ISMM4
2014 Hardware-enhanced distributed access enforcement for role-based access control
abstract
The protection of information in enterprise and cloud platforms is growing more important and complex with increasing numbers of users who need to access resources with distinct permissions. Role-based access control (RBAC) eases administrative complexity for large-scale access control, while a client-server model can ease performance bottlenecks by distributing access enforcement across multiple servers that consult the centralized access decision policy server as needed. In this paper, we propose a new approach to access enforcement using an existing associative array hardware data structure (HWDS) to cache authorizations in a distributed system using RBAC. This HWDS approach uses hardware that has previous been demonstrated as useful for several application domains including access control, network packet routing, and generic comparison-based integer search algorithms. We reproduce experiments from prior work on distributed access enforcement for RBAC systems, and we design and conduct new experiments to evaluate HWDS-based access enforcement. Experimental data show the HWDS cuts session initiation time by about a third compared to existing solutions, while achieving similar performance to authorize access requests. These results suggest that distributed systems using RBAC could use HWDS-based access enforcement to increase session throughput or to decrease the number of access enforcement servers without losing performance.
Gedare Bloom, Rahul Simha
SACMAT1
2012 No Principal Too Small: Memory Access Control for Fine-Grained Protection Domains
abstract
Modern programs comprise multiple threads of execution inside a single principal -- the process -- with a single protection domain, usually a page table. We propose a hardware enforced, fine-grained memory protection mechanism to divide the process into smaller principals and multiple protection domains. Our approach supports modern software engineering better than traditional processes by enabling developers to align software components with protection mechanisms. We implemented our architecture using a cycle-accurate simulator of a complex out-of-order pipeline and evaluate our solution using open-source benchmarks and synthetic micro benchmarks designed specifically to stress our system.
Eugen Leontie, Gedare Bloom, Bhagirath Narahari, Rahul Simha
DSD2
2012 Shared hardware data structures for hard real-time systems
abstract
Hardware support can reduce the time spent operating on data structures by exploiting circuit-level parallelism. Such hardware data structures (HWDSs) can reduce the latency and jitter of data structure operations, which can benefit real-time systems by reducing worst-case execution times (WCETs). For example, a hardware priority queue (HWPQ) can enqueue and dequeue prioritized items in constant time with low variance; the best software implementations are in logarithmic-time asymptotic complexity for at least one of the enqueue or dequeue operations. The main problems with HWDSs are the limited size of hardware and the complexity of sharing it. In this paper we show that software support can help circumvent the size and sharing limitations of hardware so that applications can benefit from a HWDS. We evaluate our work by showing how the choice of software or hardware affects schedulability of task sets that use multiple priority queues of varying sizes. We model task behavior on two applications that are important in real-time and embedded domains: the grey-weighted distance transform for topology mapping and Dijkstra's algorithm for GPS navigation. Our results indicate that HWDSs can reduce the WCET of applications even when a HWDS is shared by multiple data structures or when data structure sizes exceed HWDS size constraints.
Gedare Bloom, Gabriel Parmer, Bhagirath Narahari, Rahul Simha
EMSOFT1
2009 Providing secure execution environments with a last line of defense against Trojan circuit attacks
Gedare Bloom, Bhagirath Narahari, Rahul Simha, Joseph Zambreno
Comput. Secur.1