IoT-CODIFT: Compiler Optimization DIFT for IoT and Embedded Devices

Christopher Brant, Uday Kiran Sunkara, Janise Y. McNair · 2025

The proliferation of the Internet of Things (IoT) and embedded devices has ushered in a new generation of apps and programs to run on these devices. Unfortunately, new apps/programs can introduce cyber security vulnerabilities due to spurious information fl ows from untrusted sources, e.g., in-memory injection and other control hijacking attacks. Dynamic Information Flow Tracking (DIFT) techniques are a long-established approach to device behavioral analysis, but only for well-resourced, well-powered, full provenance computing systems. For resource constrained IoT and embedded devices, DIFT can be a prohibitive burden, and lightweight techniques have only recently begun to be investigated. This work proposes a lightweight, compiler-based DIFT system for IoT and embedded devices called CO-DIFT. CO-DIFT uses the LLVM compiler infrastructure as a framework, and security instructions are embedded directly into the executable code to prevent control fl ow attacks. Furthermore, to address the common use of heterogeneous devices in IoT, CO-DIFT is one of the few approaches designed to be machine-agnostic. The LLVM compiler infrastructure can be built and confi gured with any target machine or architecture as a hardware target that can support the storing and accessing tag memory operations. While full provenance DIFT systems show very large slowdowns, e.g., a FAROS 56x slowdown, CO-DIFT exhibits approximated slowdowns in the range 1.75x to 2.35x, drastically improving conditions for embedded IoT security operations.

Read the paper · More papers on PaperTik