The Grenade Timer: Fortifying the Watchdog Timer Against Malicious Mobile Code
Frank Stajano, Ross Anderson · 2000
Systems accepting mobile code need protection from denial of service attacks staged by the guest program. While protected mode is the most general solution, it is not available to the very low-cost microcontrollers that are common in embedded systems. In this paper we introduce the grenade timer, an evolution of the watchdog timer that can place a hard upper bound on the amount of processor time that guest code may consume. Unlike its predecessor, it is resistant to malicious attacks from the software it controls; but its structure remains extremely simple and maps to very frugal hardware resources. Keywords: mobile agents, security, denial of service, watchdog timer. 1 Introduction We move towards a scenario of ubiquitous computing: all around us, payment cards, vehicles, consumer electronics, white goods and o#ce equipment already have computing capabilities, which will be further enhanced when coupled with short range wireless telecommunications facilities [2, 9, 12]. In the fut...