{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:30:32Z","timestamp":1750307432153,"version":"3.41.0"},"reference-count":34,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2011,4,1]],"date-time":"2011-04-01T00:00:00Z","timestamp":1301616000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000144","name":"Division of Computer and Network Systems","doi-asserted-by":"publisher","award":["CNS-0720110"],"award-info":[{"award-number":["CNS-0720110"]}],"id":[{"id":"10.13039\/100000144","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2011,4]]},"abstract":"<jats:p>The incidence of malicious code and software vulnerability exploits on embedded platforms is constantly on the rise. Yet, little effort is being devoted to combating such threats to embedded systems. Moreover, adapting security approaches designed for general-purpose systems generally fails because of the limited processing capabilities of their embedded counterparts.<\/jats:p>\n          <jats:p>\n            In this work, we evaluate a malware and software vulnerability exploit defense framework for embedded systems. The proposed framework extends our prior work, which defines two isolated execution environments: a\n            <jats:italic>testing<\/jats:italic>\n            environment, wherein an untrusted application is first tested using dynamic binary instrumentation (DBI), and a\n            <jats:italic>real<\/jats:italic>\n            environment, wherein a program is monitored at runtime using an extracted behavioral model, along with a continuous learning process. We present a suite of software and hardware optimizations to reduce the overheads induced by the defense framework on embedded systems. Software optimizations include the usage of static analysis, complemented with DBI in the testing environment (i.e., a hybrid software analysis approach is used). Hardware optimizations exploit parallel processing capabilities of multiprocessor systems-on-chip.\n          <\/jats:p>\n          <jats:p>We have evaluated the defense framework and proposed optimizations on the ARM-Linux operating system. Experiments demonstrate that our framework achieves a high coverage of considered security threats, with acceptable performance penalties (the average execution time of applications goes up to 1.68X, considering all optimizations, which is much smaller than the 2.72X performance penalty when no optimizations are used).<\/jats:p>","DOI":"10.1145\/1952522.1952526","type":"journal-article","created":{"date-parts":[[2011,5,3]],"date-time":"2011-05-03T12:48:53Z","timestamp":1304426933000},"page":"1-23","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["A framework for defending embedded systems against software attacks"],"prefix":"10.1145","volume":"10","author":[{"given":"Najwa","family":"Aaraj","sequence":"first","affiliation":[{"name":"Princeton University, Princeton, NJ"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anand","family":"Raghunathan","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, IN"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Niraj K.","family":"Jha","sequence":"additional","affiliation":[{"name":"Princeton University, Princeton, NJ"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2011,5,5]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70542-0_4"},{"key":"e_1_2_1_2_1","unstructured":"Cabir. 2004. Virus descriptions: Cabir. http:\/\/www.disklabs.com\/cabir.asp.  Cabir. 2004. Virus descriptions: Cabir. http:\/\/www.disklabs.com\/cabir.asp."},{"key":"e_1_2_1_3_1","unstructured":"Cert. 2007. Vulnerability notes database. Computer Emergency Response Team. Carnegie Mellon University Pittsburgh PA. http:\/\/www.kb.cert.org\/vuls.  Cert. 2007. Vulnerability notes database. Computer Emergency Response Team. Carnegie Mellon University Pittsburgh PA. http:\/\/www.kb.cert.org\/vuls."},{"volume-title":"Proceedings of the USENIX Security Symposium. 177--192","author":"Chen S.","key":"e_1_2_1_4_1"},{"key":"e_1_2_1_5_1","unstructured":"ELFCrypt. 2005. http:\/\/www.infogreg.com\/source-code\/public-domain\/elfcrypt-v1.0.html.  ELFCrypt. 2005. http:\/\/www.infogreg.com\/source-code\/public-domain\/elfcrypt-v1.0.html."},{"key":"e_1_2_1_6_1","unstructured":"FindBugs. 2007. http:\/\/findbugs.sourceforge.net.  FindBugs. 2007. http:\/\/findbugs.sourceforge.net."},{"key":"e_1_2_1_7_1","unstructured":"Flexispy. 2006. Flexispy spills blackberry secrets. http:\/\/www.flexispy.com\/news-flexispy-blackberry -windows-mobile.htm.  Flexispy. 2006. Flexispy spills blackberry secrets. http:\/\/www.flexispy.com\/news-flexispy-blackberry -windows-mobile.htm."},{"volume-title":"Proceedings of the Network and Distributed Systems Security Symposium 191--206","author":"Garfinkel T.","key":"e_1_2_1_8_1"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/261640.261644"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/581339.581377"},{"key":"e_1_2_1_11_1","unstructured":"Kaspersky Lab. 2007. Anti-virus system protects mobile devices. http:\/\/rfdesign.com\/next_generation_wireless\/news\/kaspersky-anti-virus-mobile-devices-0208.  Kaspersky Lab. 2007. Anti-virus system protects mobile devices. http:\/\/rfdesign.com\/next_generation_wireless\/news\/kaspersky-anti-virus-mobile-devices-0208."},{"volume-title":"Proceedings of the USENIX Security Symposium. 191--206","author":"Kiriansky V.","key":"e_1_2_1_12_1"},{"volume-title":"Proceedings of the USENIX Security Symposium. 18--35","author":"Kruegel C.","key":"e_1_2_1_13_1"},{"volume-title":"Proceedings of the USENIX Security Symposium. 14--26","author":"Larochelle D.","key":"e_1_2_1_14_1"},{"key":"e_1_2_1_15_1","unstructured":"McAfee. 2007. McAfee virusscanmobile proven security on the go. http:\/\/us.mcafee.com\/root\/landingpages\/afflandpage.asp?lpname=vs_mobile.  McAfee. 2007. McAfee virusscanmobile proven security on the go. http:\/\/us.mcafee.com\/root\/landingpages\/afflandpage.asp?lpname=vs_mobile."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/AINA.2006.192"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/PERCOMW.2005.86"},{"volume-title":"Proceedings of the Conference on Network and Distributed System Security Symposium.","author":"Newsome J.","key":"e_1_2_1_18_1"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.24"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029894.1029901"},{"volume-title":"QEMU: Open source processor emulator","year":"2008","author":"Qemu","key":"e_1_2_1_21_1"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1015047.1015049"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/49.622919"},{"key":"e_1_2_1_24_1","unstructured":"Secunia. 2007. Vulnerabilities and virus information. http:\/\/secunia.com.  Secunia. 2007. Vulnerabilities and virus information. http:\/\/secunia.com."},{"key":"e_1_2_1_25_1","unstructured":"Sharp. 2002. Device profile: Sharp's Zaurus SL-5500 Linux PDA. http:\/\/www.linuxdevices.com\/articles\/AT2134869242.html.  Sharp. 2002. Device profile: Sharp's Zaurus SL-5500 Linux PDA. http:\/\/www.linuxdevices.com\/articles\/AT2134869242.html."},{"key":"e_1_2_1_26_1","unstructured":"Simics. 2004. Virtutech Simics. http:\/\/www.virtutech.com\/whatissimics.html.  Simics. 2004. Virtutech Simics. http:\/\/www.virtutech.com\/whatissimics.html."},{"key":"e_1_2_1_27_1","unstructured":"SimIt-ARM. 2007. http:\/\/simit-arm.sourceforge.net.  SimIt-ARM. 2007. http:\/\/simit-arm.sourceforge.net."},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1023646.1023658"},{"key":"e_1_2_1_29_1","unstructured":"UPX. 2007. The Ultimate Packer for eXecutables. http:\/\/upx.sourceforge.net.  UPX. 2007. The Ultimate Packer for eXecutables. http:\/\/upx.sourceforge.net."},{"volume-title":"Proceedings of the Australasian Computer Science Conference 311--320","author":"Vasudevan A.","key":"e_1_2_1_30_1"},{"key":"e_1_2_1_31_1","unstructured":"VX Heavens. 2007. http:\/\/vx.netlux.org.  VX Heavens. 2007. http:\/\/vx.netlux.org."},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/103135.103136"},{"volume-title":"Proceedings of the Network and Distributed System Security Symposium.","author":"Wilander J.","key":"e_1_2_1_33_1"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315261"}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1952522.1952526","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1952522.1952526","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T11:39:55Z","timestamp":1750246795000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1952522.1952526"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,4]]},"references-count":34,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2011,4]]}},"alternative-id":["10.1145\/1952522.1952526"],"URL":"https:\/\/doi.org\/10.1145\/1952522.1952526","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"type":"print","value":"1539-9087"},{"type":"electronic","value":"1558-3465"}],"subject":[],"published":{"date-parts":[[2011,4]]},"assertion":[{"value":"2008-12-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2009-09-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-05-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}