Matches in SemOpenAlex for { <https://semopenalex.org/work/W4381337444> ?p ?o ?g. }
Showing items 1 to 66 of
66
with 100 items per page.
- W4381337444 endingPage "217" @default.
- W4381337444 startingPage "217" @default.
- W4381337444 abstract "With the increasing popularity of IoT (Internet-of-Things) devices, their security becomes an increasingly important issue. Buffer overflow vulnerabilities have been known for decades, but are still relevant, especially for embedded devices where certain security measures cannot be implemented due to hardware restrictions or simply due to their impact on performance. Therefore, many buffer overflow detection mechanisms check for overflows only before critical data are used. All data that an attacker could use for his own purposes can be considered critical. It is, therefore, essential that all critical data are checked between writing a buffer and its usage. This paper presents a vulnerability of the ESP32 microcontroller, used in millions of IoT devices, that is based on a pointer that is not protected by classic buffer overflow detection mechanisms such as Stack Canaries or Shadow Stacks. This paper discusses the implications of vulnerability and presents mitigation techniques, including a patch, that fixes the vulnerability. The overhead of the patch is evaluated using simulation as well as an ESP32-WROVER-E development board. We showed that, in the simulation with 32 general-purpose registers, the overhead for the CoreMark benchmark ranges between 0.1% and 0.4%. On the ESP32, which uses an Xtensa LX6 core with 64 general-purpose registers, the overhead went down to below 0.01%. A worst-case scenario, modeled by a synthetic benchmark, showed overheads up to 9.68%." @default.
- W4381337444 created "2023-06-21" @default.
- W4381337444 creator A5042352640 @default.
- W4381337444 creator A5086912004 @default.
- W4381337444 date "2023-06-19" @default.
- W4381337444 modified "2023-10-01" @default.
- W4381337444 title "Through the Window: Exploitation and Countermeasures of the ESP32 Register Window Overflow" @default.
- W4381337444 cites W1968002620 @default.
- W4381337444 cites W2039789481 @default.
- W4381337444 cites W2159059513 @default.
- W4381337444 cites W2172131317 @default.
- W4381337444 cites W2293825325 @default.
- W4381337444 cites W2809973595 @default.
- W4381337444 cites W2883468219 @default.
- W4381337444 cites W2899759798 @default.
- W4381337444 cites W3087256628 @default.
- W4381337444 cites W4281896075 @default.
- W4381337444 cites W4312492813 @default.
- W4381337444 cites W4313562895 @default.
- W4381337444 doi "https://doi.org/10.3390/fi15060217" @default.
- W4381337444 hasPublicationYear "2023" @default.
- W4381337444 type Work @default.
- W4381337444 citedByCount "0" @default.
- W4381337444 crossrefType "journal-article" @default.
- W4381337444 hasAuthorship W4381337444A5042352640 @default.
- W4381337444 hasAuthorship W4381337444A5086912004 @default.
- W4381337444 hasBestOaLocation W43813374441 @default.
- W4381337444 hasConcept C111919701 @default.
- W4381337444 hasConcept C149635348 @default.
- W4381337444 hasConcept C173018170 @default.
- W4381337444 hasConcept C2779960059 @default.
- W4381337444 hasConcept C31258907 @default.
- W4381337444 hasConcept C38652104 @default.
- W4381337444 hasConcept C40842320 @default.
- W4381337444 hasConcept C41008148 @default.
- W4381337444 hasConcept C95713431 @default.
- W4381337444 hasConceptScore W4381337444C111919701 @default.
- W4381337444 hasConceptScore W4381337444C149635348 @default.
- W4381337444 hasConceptScore W4381337444C173018170 @default.
- W4381337444 hasConceptScore W4381337444C2779960059 @default.
- W4381337444 hasConceptScore W4381337444C31258907 @default.
- W4381337444 hasConceptScore W4381337444C38652104 @default.
- W4381337444 hasConceptScore W4381337444C40842320 @default.
- W4381337444 hasConceptScore W4381337444C41008148 @default.
- W4381337444 hasConceptScore W4381337444C95713431 @default.
- W4381337444 hasFunder F4320321114 @default.
- W4381337444 hasIssue "6" @default.
- W4381337444 hasLocation W43813374441 @default.
- W4381337444 hasOpenAccess W4381337444 @default.
- W4381337444 hasPrimaryLocation W43813374441 @default.
- W4381337444 hasRelatedWork W1523637658 @default.
- W4381337444 hasRelatedWork W1569451733 @default.
- W4381337444 hasRelatedWork W183168643 @default.
- W4381337444 hasRelatedWork W1905160682 @default.
- W4381337444 hasRelatedWork W2264218242 @default.
- W4381337444 hasRelatedWork W2353840198 @default.
- W4381337444 hasRelatedWork W2353926745 @default.
- W4381337444 hasRelatedWork W2354094736 @default.
- W4381337444 hasRelatedWork W2373025652 @default.
- W4381337444 hasRelatedWork W3015380456 @default.
- W4381337444 hasVolume "15" @default.
- W4381337444 isParatext "false" @default.
- W4381337444 isRetracted "false" @default.
- W4381337444 workType "article" @default.