Timing covert channel analysis of the VxWorks MILS embedded hypervisor under the common criteria security certification

Domenico Cotroneo,Luigi De Simone,Roberto Natella
DOI: https://doi.org/10.1016/j.cose.2021.102307
2021-07-01
Abstract:<p>Virtualization technology is nowadays adopted in security-critical embedded systems to achieve higher performance and more design flexibility. However, it also comes with new security threats, where attackers leverage <em>timing covert channels</em> to exfiltrate sensitive information from a partition using a trojan. This paper presents a novel approach for the experimental assessment of timing covert channels in embedded hypervisors, with a case study on security assessment of a commercial hypervisor product (<em>Wind River VxWorks MILS</em>), in cooperation with a licensed laboratory for the <em>Common Criteria</em> security certification. Our experimental analysis shows that it is indeed possible to establish a timing covert channel, and that the approach is useful for system designers for assessing that their configuration is robust against this kind of information leakage.</p>
computer science, information systems
What problem does this paper attempt to address?