Exception-Driven Security: A Risk-Aware Permission Adjustment for High-Availability Embedded Systems
Abstract
1. Introduction
2. Problem State and Motivation
2.1. Tamper-Proof System Call Code
2.2. Compliance for Privilege Separation
2.3. Real-Time Guarantees
3. Contribution
- Presents an in-depth examination of RTOS architectures and their features, with a focus on identifying and analyzing security vulnerabilities (particularly in syscall design) and the inherent challenges of building secure, tamper-resistant embedded systems.
- Proposes a dynamic security model that augments CHERI’s memory protection capabilities through adaptive policy enforcement. By monitoring CHERI-triggered exceptions, the framework detects anomalous behavior and dynamically adjusts permissions to contain security threats without disrupting essential system operations.
- Performs a detailed evaluation of the proposed framework’s impact on both security and system performance. Two case studies are presented to demonstrate its effectiveness in handling security violations while preserving the integrity, availability, and real-time properties of the operating system.
4. Background
4.1. Real-Time Operating System
4.2. FreeRTOS Services
4.2.1. Memory Management
4.2.2. Task Management
4.2.3. Inter-Task Communication
4.2.4. Resource Management
4.3. An Introduction to CHERI
- Tag bit (1 bit): Indicates whether a valid capability is present in a register or memory. If set, the capability is valid and can be dereferenced (subject to additional checks). If clear, the capability is invalid.
- Permissions mask (perms): Defines hardware-enforced access rights, with the first 12 bits. Permissions are limited by the current architectural ring and influenced by the tag.
- Flags (f): An architecture-specific field accessible via CGetFlags (read) and CSetFlags (write). No architecture-neutral flags are defined.
- Object type (otype, 4 bits for 64-bit: Specifies whether the capability is sealed and its type. Sealed capabilities are immutable and non-dereferenceable; they can be unsealed with CUnseal or through control transfer instructions CInvoke, CJALR).
- Bounds: Encodes the lower and upper limits of the memory region that the capability can reference. Bounds are compressed relative to the address and enforce spatial memory safety by preventing out-of-range accesses.
5. Related Work
6. Design Overview
| Listing 1. Capability structure in the code. |
![]() |
| Listing 2. Pseudo-code for a Load Instruction Using my_cap. |
![]() |
6.1. Risk Detection Mechanism
- Risk: Any unusual behavior that deviates from expected operations may indicate a potential security breach. CHERI utilizes hardware-enforced capabilities to provide fine-grained memory protection and prevent unauthorized access. These capabilities trigger exceptions when a thread, compartment, or other task entity attempts an action that violates defined permissions, such as accessing memory outside bounds or performing operations without the required privileges. We leverage these exceptions to define a quantitative variable called the Risk Score, calculated based on exception features discussed later in this chapter. When an exception occurs in CHERI, specific registers capture detailed information, including the type and cause of the exception and the address of the faulting memory reference. These registers include the following:
- –
- mcause: Machine Cause register (32 bits); contains the cause of the standard RISC-V exception or interrupt.
- –
- mepc: Machine Exception Program Counter register (32 bits); stores the address of the instruction that caused the exception.
- –
- mtval: Machine Trap Value register (32 bits); holds exception-specific information to assist in handling capability-related exceptions, as illustrated in Figure 2.
The proposed model focuses on using the mtval register to extract relevant exception information. As shown in Listing 3, register decoding interprets the fields as follows:- –
- capcause = mtval & 0x1f: Extracts the lower 5 bits of mtval (see Table 2).
- –
- badcap = (mtval 5) & 0x3f: Extracts bits 5–10 of mtval.
| Listing 3. CHERIoT-RTOS core scheduler initialization. |
![]() |
- Risk Monitoring—To assess security risks, the system continuously monitors and logs recently triggered exceptions, computing a risk score using two complementary approaches:
- –
- Thread-based monitoring: Exceptions are recorded at the thread level to track the number and type of faults each thread triggers.
- –
- Compartment-based monitoring: Exceptions are recorded per compartment to detect broader fault patterns and evaluate the security posture of each compartment. In CHERI, a compartment is an isolated execution context enforcing strict memory safety via hardware capabilities. Each compartment consists of a Program Counter Capability (PCC) for executing code and accessing read-only data, a Capability Global Pointer (CGP) for mutable global variables, and an import/export interface for secure interactions with other compartments or external resources.
Regardless of monitoring scope, exception attributes are evaluated to determine criticality:- –
- Exception Severity: Mapped from the predefined CHERI exception list and its associated impact score (Table 2).
- –
- Exception Frequency: Number of exceptions triggered by a thread or compartment within the current monitoring window.
- –
- Average Exception Interval: Mean time between consecutive exceptions for a given thread or compartment, indicating fault rate.
- Risk Table—At the core of the monitoring algorithm is a risk table that logs exception-related metadata and correlates it with threads or compartments. Key fields include the following:
- –
- Thread/Compartment ID: Unique identifier of the faulting entity.
- –
- CapCause: Cause of the exception as recorded in the mtval register, corresponding to the values in Table 2.
- –
- Count: Total number of exceptions recorded for the entity within the monitoring window (capped by CONFIG_MAX_CHERI_EXCEPTIONS).
- –
- Timestamp: Time of the most recent exception.
- –
- Avg Interval: Average time gap between recent exceptions.
- –
- Window_Start: Start time of the current 5000 ms sliding monitoring window. Exceptions outside this window are discarded, and counts reset at each window rollover.
The CHERI RTOS operates with statically defined threads and fixed stack sizes. By default, the system supports eight threads, configurable up to 255. In our implementation of thread-based monitoring, the risk table retains records for the 16 most recent threads that have triggered exceptions.To accurately present the exception rate in a CHERI-based RTOS, two bounding parameters must be considered:- –
- Scheduler tick frequency—Typically ranging from 1 to 10 kHz, configurable via the CONFIG_SCHEDULER_TICK_FREQ option in the SDK headers.
- –
- Execution context—Determines how often a faulty thread can trigger exceptions, potentially on every cycle. For example, an infinite loop performing repeated capability violations could generate exceptions at maximum frequency. In practice, hardware watchdogs or compartment-level timeouts (e.g., via thread_sleep) eventually preempt such behavior.
Table 4 outlines the risk table format, including the size of each entry and the possible value ranges.
| Field | Type | Size (Bytes) | Ranges |
|---|---|---|---|
| Thread ID | uint16_t | 2 | 0x01–0xFFFF |
| CapCause | uint8_t | 1 | 0x01–0x18 |
| Count | uint8_t | 1 | 0–20 |
| Timestamp | uint64_t | 8 | Timestamp |
| Avg Interval | uint32_t | 4 | 10–5000 ms |
- Risk Score—The risk score is designed to provide a comprehensive assessment of potential security threats, relying solely on exception severity risks overlooking scenarios in which frequent but less severe exceptions indicate a deeper issue. To address this, we employ a composite equation that integrates multiple exception attributes, yielding a more balanced and accurate risk evaluation.Updating the risk table involves the following steps:
- Record the cause of the newly triggered exception.
- Increment the exception count for the corresponding thread or compartment.
- Calculate the time interval between the two most recent exceptions to estimate exception frequency.
- Update the timestamp to reflect the latest occurrence.
- Compute using Equation (1).
where- –
- [0, 1]: The risk score that represents the degree of abnormal behavior per thread or compartment.
- –
- : Task or comportment ID.
- –
- [0.01, 0.1]: A weight parameter that controls the relative importance of the impact score.
- –
- [0, 10]: Impact score or severity score assigned to the exception based on the impact score table.
- –
- [0, 10]: Count of exceptions triggered by a particular thread or compartment.
- –
- [0.01, 0.05]: A weighting factor (ranging from 0 to 1) that adjusts the impact of the time interval between exceptions on the risk score.
- –
- [10, 5000 ms]: The average interval represents the time (in milliseconds) between the most recent exception and the preceding one for a specific task.
- x = 0.5 (Middle threshold)—In high-alert mode, any risk score above 0 and below 0.5 triggers mitigation actions, enabling a more sensitive response to potential threats.
- y = 0.7 (Upper threshold)—In normal mode, risk scores below 0.7 trigger mitigation actions, while scores above 0.7 indicate a more severe risk.
6.2. Permission Adjustment
7. Implementation and Evaluation
- Continuous Operation: Maintains system functionality during capability violations without requiring full thread termination.
- Precision Security: Selectively revokes permissions (e.g., Execute, Load, Store, and Seal) based on the violation type.
- Progressive Containment: Gradually reduces capability bounds to minimize potential damage.
- Policy-Driven Responses: Enables configurable, context-aware mitigation strategies tailored to the nature of each violation.
7.1. Security Effectiveness Evaluation
- Twenty real-world CVEs: These vulnerabilities, listed in Table 6, were selected for their relevance to FreeRTOS and similar platforms. Each was modeled and executed on both a standard FreeRTOS system and our RPA-enhanced CHERIoT system. This approach allowed us to directly compare baseline and mitigated behaviors.
| CVE ID | FreeRTOS | Proposed RPA |
|---|---|---|
| CVE-2018-16522 | Privilege escalation | ✓ |
| CVE-2018-16523 | Data corruption or DoS | ✓ |
| CVE-2018-16524 | Data corruption or crash | ✓ |
| CVE-2018-16525 | Remote code execution | ✓ |
| CVE-2018-16526 | System crash, DoS | ✓ |
| CVE-2018-16527 | Information leak | ✓ |
| CVE-2018-16528 | Remote code execution | ✓ |
| CVE-2018-16598 | Memory corruption | ✓ |
| CVE-2018-16599 | Memory disclosure | ✓ |
| CVE-2018-16600 | Memory disclosure | ✓ |
| CVE-2018-16601 | Memory disclosure | ✓ |
| CVE-2018-16602 | Memory disclosure | × |
| CVE-2018-16603 | Memory disclosure | × |
| CVE-2019-13120 | Code execution | ✓ |
| CVE-2021-31571 | Privilege escalation | ✓ |
| CVE-2021-31572 | Privilege escalation | ✓ |
| CVE-2021-32020 | Privilege escalation | ✓ |
| CVE-2021-43997 | Memory disclosure | ✓ |
| CVE-2024-28115 | Stack-based buffer overflow | ✓ |
| CVE-2024-38373 | Arbitrary code execution | ✓ |
- Fifteen abstract vulnerability classes: To assess generalizability, we synthesized attacks representing common exploitation techniques (e.g., stack smashing, heap spraying, and privilege escalation). These are summarized in Table 7 and were executed exclusively on the RPA-enhanced system.
| Vulnerability | FreeRTOS | Proposed RPA |
|---|---|---|
| Stack smashing | Overwrites return address | Stack bounds enforced |
| Pointer overwrite | Arbitrary code execution | Indirect calls restricted |
| Double free | Heap corruption | Capability invalidation free |
| Format string | Memory disclosure | Memory access restricted |
| Integer overflow | Buffer overflow | Bounds check enforced |
| Data exfiltration | Sensitive data leak | Memory sealing compartments |
| Race condition | Data race, privilege escalation | Fine-grained compartments |
| TOCTOU | Privilege escalation, data race | Unforgeable checked capabilities |
| Task hijacking | Malicious code execution | Task isolation compartments |
| Stack overflow | System crash, code execution | Stack bounds enforced |
| Buffer over-read | Information leak | Readable memory restricted |
| Memory leak | Resource exhaustion, DoS | Capabilities tracked revoked |
| ROP | Code reuse attack | Arbitrary execution prevented |
| Heap spraying | Increases exploit reliability | Forged pointers prevented |
| Task starvation | Denial of service | Fine-grained scheduling |
| Listing 4. CVE-2018-16522. |
![]() |
7.2. Runtime Overhead and Availability Valuation
8. Conclusions
9. Future Direction
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
Abbreviations
| AC | Access Control |
| ACL | Access Control List |
| ACT | Access Control Table |
| ARM | Advanced RISC Machine |
| API | Application Programming Interface |
| CPS | Cyber–Physical Systems |
| CGP | Capability Global Pointer |
| CSR | Control and Status Registers |
| CVE | Common Vulnerabilities and Exposures |
| CWE | Common Weakness Enumeration |
| DDC | Default Data Capability |
| DMA | Direct Memory Access |
| EROS | Extremely Reliable Operating System |
| ES | Embedded Systems |
| EOS | Embedded Operating Systems |
| FPU | Floating Point Unit |
| GPR | General-Purpose Registers |
| HAL | Hardware Abstraction Layer |
| ML | Machine Learning |
| MMU | Memory Management Unit |
| MMP | Mondrian Memory Protection |
| MPD | Mutable Protection Domains |
| MPU | Memory Protection Unit |
| MQTT | Message Queuing Telemetry Transport |
| PCC | Program Counter Capability |
| RBAC | Role-Based Access Control |
| RPA | Risk-aware Permission Adjustment |
| RTOS | Real-Time Operating System |
References
- Murti, K.C.S. Security in embedded systems. In Design Principles for Embedded Systems; Springer: Singapore, 2022; pp. 419–441. [Google Scholar]
- Varastan, B.; Jamali, S.; Fotohi, R. Hardening of the Internet of Things by using an intrusion detection system based on deep learning. Clust. Comput. 2023, 27, 2465–2488. [Google Scholar] [CrossRef] [Scilit]
- Longueira-Romero, A.; Iglesias, R.; Gonzalez, D.; Garitano, I. How to quantify the security level of embedded systems? A taxonomy of security metrics. In Proceedings of the 18th International Conference on Industrial Informatics (INDIN), Warwick, UK, 20–23 July 2020; Volume 1, pp. 153–158. [Google Scholar]
- Luna, R.; Islam, S.A. Security and reliability of safety-critical RTOS. SN Comput. Sci. 2021, 2, 356. [Google Scholar] [CrossRef] [Scilit]
- Labs, A. Critical Flaws Found in VxWorks RTOS That Powers Over 2 Billion Devices. Detailed Report on Multiple Zero-Day Vulnerabilities Termed URGENT/11, Affecting VxWorks RTOS Across Many Industries, Enabling Remote Code Execution and Denial-of-Service Attacks. 2019. Available online: https://thehackernews.com/2019/07/vxworks-rtos-vulnerability.html (accessed on 10 August 2025).
- Journal, H. Medical Devices Affected by 13 Siemens Nucleus RTOS TCP/IP Stack Vulnerabilities. Summary of Critical Vulnerabilities Discovered in Siemens Nucleus RTOS Affecting Medical Devices, Highlighting Risks of Remote Exploitation and Need for Urgent Mitigation. 2024. Available online: https://www.hipaajournal.com/medical-devices-affected-by-13-siemens-nucleus-rtos-tcp-ip-stack-vulnerabilities/ (accessed on 10 August 2025).
- VulnCheck. Danger Is Still Lurking in the NVD Backlog. 2024. Available online: https://vulncheck.com/blog/nvd-backlog-exploitation-lurking (accessed on 10 August 2025).
- Magazine, I. NVD Revamps Operations as Vulnerability Reporting Surges. 2025. Available online: https://www.infosecurity-magazine.com/news/nvd-revamps-operations-cve-surge/ (accessed on 10 August 2025).
- NIST. CVE-2024-28115 Detail—FreeRTOS Local Privilege Escalation. 2024. Available online: https://nvd.nist.gov/vuln/detail/CVE-2024-28115 (accessed on 20 July 2025).
- NIST. CVE-2025-35003 Detail—Apache NuttX RTOS Vulnerability. 2025. Available online: https://nvd.nist.gov/vuln/detail/CVE-2025-35003 (accessed on 20 July 2025).
- VulnCheck. 2025 Q1 Trends in Vulnerability Exploitation. 2025. Available online: https://vulncheck.com/blog/exploitation-trends-q1-2025 (accessed on 10 August 2025).
- SecPod. The Cybersecurity Landscape of 2024: Key Insights from the Annual Vulnerability Report. 2025. Available online: https://www.secpod.com/blog/the-cybersecurity-landscape-of-2024-key-insights-from-the-annual-vulnerability-report/ (accessed on 10 August 2025).
- MITRE. Common Weakness Enumeration (CWE). Available online: https://cwe.mitre.org/ (accessed on 20 July 2025).
- CVE Details. Vulnerabilities by Types. Available online: https://www.cvedetails.com/vulnerabilities-by-types.php (accessed on 20 July 2025).
- 2023. Available online: https://github.com/FreeRTOS/FreeRTOS (accessed on 1 June 2025).
- AWS. FreeRTOS Security Updates. 2023. Available online: https://aws.amazon.com/freertos/security-updates/ (accessed on 1 June 2025).
- Walls, R.J.; Brown, N.F.; Le Baron, T.; Shue, C.A.; Okhravi, H.; Ward, B.C. Control-flow integrity for real-time embedded systems. In Proceedings of the 31st Euromicro Conference on Real-Time Systems (ECRTS), Stuttgart, Germany, 9–12 July 2019. [Google Scholar]
- FreeRTOS Plus. FreeRTOS+Trace. 2023. Available online: https://www.freertos.org/Documentation/03-Libraries/02-FreeRTOS-plus/05-FreeRTOS_plus_Trace/00-FreeRTOS_Plus_Trace (accessed on 10 October 2025).
- Malenko, M.; Baunach, M. Device driver and system call isolation in embedded devices. In Proceedings of the 22nd Euromicro Conference on Digital System Design (DSD), Kallithea, Greece, 28–30 August 2019; pp. 283–290. [Google Scholar]
- Chandrasekaran, P.; Kumar, K.S.; Minz, R.L.; D’Souza, D.; Meshram, L. A multi-core version of FreeRTOS verified for datarace and deadlock freedom. In Proceedings of the Twelfth Conference on Formal Methods and Models for Codesign (MEMOCODE), Lausanne, Switzerland, 19–21 October 2014; pp. 62–71. [Google Scholar]
- Holzmann, G.J. The model checker SPIN. IEEE Trans. Softw. Eng. 1997, 23, 279–295. [Google Scholar] [CrossRef] [Scilit]
- Xia, H.; Woodruff, J.; Barral, H.; Esswood, L.; Joannou, A.; Kovacsics, R.; Chisnall, D.; Roe, M.; Davis, B.; Napierala, E.; et al. CheriRTOS: A Capability Model for Embedded Devices. In Proceedings of the 36th International Conference on Computer Design (ICCD), Orlando, FL, USA, 7–10 October 2018; pp. 92–99. [Google Scholar]
- Memory Protection Unit (MPU) Support in FreeRTOS. 2022. Available online: http://www.openrtos.org/FreeRTOS-MPU-memory-protection-unit.html (accessed on 5 October 2025).
- High Integrity Systems. Building on FreeRTOS for Safety Critical Applications. 2022. Available online: https://www.highintegritysystems.com/downloads/white_papers/Building_on_FreeRTOS_Safety_Critical_Applications.pdf (accessed on 1 June 2025).
- Almatary, H.; Dodson, M.; Clarke, J.; Rugg, P.; Gomes, I.; Podhradský, M.; Neumann, P.G.; Moore, S.W.; Watson, R.N.M. CompartOS: CHERI Compartmentalization for Embedded Systems. arXiv 2022, arXiv:2206.02852. [Google Scholar] [CrossRef] [Scilit]
- Bratus, S.; Johnson, P.C.; Ramaswamy, A.; Smith, S.W.; Locasto, M.E. The cake is a lie: Privilege rings as a policy resource. In Proceedings of the 1st ACM Workshop on Virtual Machine Security, Alexandria, VA, USA, 27 October 2008; pp. 33–38. [Google Scholar]
- Witchel, E.; Cates, J.; Asanović, K. Mondrian memory protection. In Proceedings of the 10th International Conference on Architectural Support for Programming Languages and OS, San Jose, CA, USA, 5–9 October 2002; pp. 304–316. [Google Scholar]
- Arm. TrustZone for Cortex-M. 2023. Available online: https://www.arm.com/technologies/trustzone-for-cortex-m (accessed on 10 June 2025).
- Using FreeRTOS on ARMv8-M Microcontrollers. Available online: https://www.freertos.org/Community/Blogs/2020/using-freertos-on-armv8-m-microcontrollers (accessed on 5 October 2025).
- OWASP Foundation. A01: Broken Access Control, OWASP Top 10. 2021. Available online: https://owasp.org/Top10/A01_2021-Broken_Access_Control/ (accessed on 10 June 2025).
- Hardy, N. The Confused Deputy. 2023. Available online: https://web.archive.org/web/20031205034929/http://www.cis.upenn.edu/~KeyKOS/ConfusedDeputy.html (accessed on 12 July 2025).
- Memory Management in FreeRTOS. 2022. Available online: https://www.freertos.org/a00111.html (accessed on 5 October 2025).
- Inter-Task Communications in FreeRTOS. Available online: https://www.freertos.org/message_passing_performance (accessed on 5 October 2025).
- Mutexes in FreeRTOS. 2023. Available online: https://www.freertos.org/Real-time-embedded-RTOS-mutexes.html (accessed on 5 October 2025).
- Semaphores in FreeRTOS. 2023. Available online: https://www.freertos.org/a00113.html (accessed on 5 October 2025).
- Binary Semaphores in FreeRTOS. 2023. Available online: https://www.freertos.org/Embedded-RTOS-Binary-Semaphores.html (accessed on 5 October 2025).
- Counting Semaphores in FreeRTOS. 2023. Available online: https://freertos.org/Real-time-embedded-RTOS-Counting-Semaphores.html (accessed on 5 October 2025).
- Tsai, T.; Singh, N. Libsafe: Transparent system-wide protection against buffer overflow attacks. In Proceedings of the International Conference on Dependable Systems and Networks, Washington, DC, USA, 23–26 June 2002; p. 541. [Google Scholar]
- Lin, Z.; Mao, B.; Xie, L. LibsafeXP: A practical and transparent tool for run-time buffer overflow preventions. In Proceedings of the Information Assurance Workshop, West Point, NY, USA, 21–23 June 2006; pp. 332–339. [Google Scholar]
- Dang, T.H.; Maniatis, P.; Wagner, D. The performance cost of shadow stacks and stack canaries. In Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security, Singapore, 14 April–17 March 2015; pp. 555–566. [Google Scholar]
- Midi, D.; Payer, M.; Bertino, E. Memory safety for embedded devices with nesCheck. In Proceedings of the ACM on Asia Conference on Computer and Communications Security, Abu Dhabi, United Arab Emirates, 2–6 April 2017; pp. 127–139. [Google Scholar]
- Dhurjati, D.; Kowshik, S.; Adve, V.; Lattner, C. Memory safety without garbage collection for embedded applications. ACM Trans. Embed. Comput. Syst. (TECS) 2005, 4, 73–111. [Google Scholar] [CrossRef] [Scilit]
- The Ruby Programming Language. A Programmer’s Best Friend. Available online: https://www.ruby-lang.org/en/ (accessed on 12 July 2025).
- Matsakis, N.D.; Klock, F.S. The rust language. In Proceedings of the ACM SIGAda Annual Conference on High Integrity Language Technology, New York, NY, USA, 18–21 October 2014; HILT ’14; pp. 103–104. [Google Scholar] [CrossRef] [Scilit]
- Rust. A Language Empowering Everyone. Available online: https://www.rust-lang.org/ (accessed on 12 July 2025).
- The Swift Programming Language. A General-Purpose Programming Language. Available online: https://www.swift.org/ (accessed on 12 July 2025).
- The seL4 Microkernel. Available online: https://sel4.systems/ (accessed on 12 July 2025).
- Siapoush, M.S.; Alves-Foss, J. Is Formal Verification of seL4 Adequate to Address the Key Security Challenges of Kernel Design? IEEE Access 2023, 11, 101750–101759. [Google Scholar] [CrossRef] [Scilit]
- Stepanov, E.; Serebryany, K. MemorySanitizer: Fast detector of uninitialized memory use in C++. In Proceedings of the International Symposium on Code Generation and Optimization (CGO), San Francisco, CA, USA, 7–11 February 2015; pp. 46–55. [Google Scholar]
- Serebryany, K.; Bruening, D.; Potapenko, A.; Vyukov, D. AddressSanitizer: A fast address sanity checker. In Proceedings of the USENIX Annual Technical Conference, Boston, MA, USA, 13–15 June 2012; pp. 309–318. [Google Scholar]
- Sasaki, H.; Arroyo, M.A.; Ziad, M.T.I.; Bhat, K.; Sinha, K.; Sethumadhavan, S. Practical byte-granular memory blacklisting using califorms. In Proceedings of the 52nd Annual IEEE/ACM International Symposium on Microarchitecture, Columbus, OH, USA, 12–16 October 2019; pp. 558–571. [Google Scholar]
- Nagarakatte, S.; Zhao, J.; Martin, M.M.; Zdancewic, S. SoftBound: Highly compatible and complete spatial memory safety for C. In Proceedings of the 30th ACM SIGPLAN Conference on Programming Language Design and Implementation, Dublin, Ireland, 15–21 June 2009; pp. 245–258. [Google Scholar]
- Nethercote, N.; Seward, J. Valgrind: A framework for heavyweight dynamic binary instrumentation. ACM Sigplan Not. 2007, 42, 89–100. [Google Scholar] [CrossRef] [Scilit]
- Coverity. Scan Static Analysis. Available online: https://scan.coverity.com/ (accessed on 5 August 2025).
- Parmer, G.; West, R. Mutable Protection Domains: Towards a Component-Based System for Dependable and Predictable Computing. In Proceedings of the 28th IEEE International Real-Time Systems Symposium, Tucson, AZ, USA, 3–6 December 2007; pp. 365–378. [Google Scholar] [CrossRef] [Scilit]
- Composite, O.S. Scalable Component-Based Operating System. Available online: https://composite.seas.gwu.edu/ (accessed on 5 August 2025).
- Harryson, M. Language-Based Permissions in Embedded Systems. Master’s Thesis, Chalmers University of Technology, University of Gothenburg, Göteborg, Sweden, 2020. [Google Scholar]
- Wang, X.; Mizuno, M.; Neilsen, M.; Ou, X.; Rajagopalan, S.R.; Boldwin, W.G.; Phillips, B. Secure RTOS Architecture for Building Automation. In Proceedings of the First ACM Workshop on Cyber-Physical Systems-Security and/or PrivaCy, New York, NY, USA, 16 October 2015; CPS-SPC’15; pp. 79–90. [Google Scholar] [CrossRef] [Scilit]
- Levy, H.M. Capability-Based Computer Systems; Digital Press: Bethlehem, PA, USA, 2014. [Google Scholar]
- Miller, M.S.; Yee, K.P.; Shapiro, J. Capability Myths Demolished. Technical Report, Technical Report SRL2003-02; Johns Hopkins University Systems Research: Baltimore, MD, USA, 2003. [Google Scholar]
- Hydra. Hydra: The Kernel of a Multiprocessor Operating System. 1971. Available online: https://homes.cs.washington.edu/~levy/capabook/Chapter6.pdf (accessed on 5 August 2025).
- The Fiasco Microkernel. Available online: https://github.com/kernkonzept/fiasco (accessed on 5 August 2025).
- Shapiro, J.S.; Smith, J.M.; Farber, D.J. EROS: A fast capability system. In Proceedings of the Seventeenth ACM Symposium on Operating Systems Principles, Charleston, SC, USA, 12–15 December 1999; pp. 170–185. [Google Scholar]
- Watson, R.N.; Anderson, J.; Laurie, B.; Kennaway, K. Capsicum: Practical Capabilities for {UNIX}. In Proceedings of the 19th USENIX Security Symposium (USENIX Security 10), Washington, DC, USA, 11–13 August 2010. [Google Scholar]
- Watson, R.N.; Woodruff, J.; Neumann, P.G.; Moore, S.W.; Anderson, J.; Chisnall, D.; Dave, N.; Davis, B.; Gudka, K.; Laurie, B.; et al. CHERI: A hybrid capability-system architecture for scalable software compartmentalization. In Proceedings of the Symposium on Security and Privacy, San Jose, CA, USA, 17–21 May 2015; pp. 20–37. [Google Scholar]
- Bakir, F.; Krintz, C.; Wolski, R. Caplets: Resource aware, capability-based access control for iot. In Proceedings of the ACM Symposium on Edge Computing (SEC), San Jose, CA, USA, 14–17 December 2021; pp. 106–120. [Google Scholar]
- Rasifard, H.; Gopinath, R.; Backes, M.; Nemati, H. SEAL: Capability-based access control for data-analytic scenarios. In Proceedings of the 28th ACM Symposium on Access Control Models and Technologies, Trento, Italy, 7–9 June 2023; pp. 67–78. [Google Scholar]
- Mettler, A.; Wagner, D.A.; Close, T. Joe-E: A Security-Oriented Subset of Java. In Proceedings of the NDSS, San Diego, CA, USA, 28 February–3 March 2010; Volume 10, pp. 357–374. [Google Scholar]
- Miller, M.S.; Samuel, M.; Laurie, B.; Awad, I.; Stay, M. Safe active content in sanitized JavaScript. Google Inc. Tech. Rep. 2008. Available online: https://google-code-archive-downloads.storage.googleapis.com/v2/code.google.com/google-caja/caja-spec-2008-06-06.pdf (accessed on 5 October 2025).
- Ferraro, D.; Bastoni, A.; Zuepke, A.; Marongiu, A. Enabling Security on the Edge: A CHERI Compartmentalized Network Stack. arXiv 2025, arXiv:2507.04818. [Google Scholar] [CrossRef] [Scilit]
- Chen, A.U. CHERIoT: A Study in CHERI. RISC-V Blog. 2024. Available online: https://riscv.org/blog/2024/08/cheriot-a-study-in-cheri/ (accessed on 5 August 2025).
- Amar, S.; Chisnall, D.; Chen, T.; Filardo, N.W.; Laurie, B.; Liu, K.; Norton, R.; Moore, S.W.; Tao, Y.; Watson, R.N.M.; et al. CHERIoT: Complete Memory Safety for Embedded Devices. In Proceedings of the 56th Annual IEEE/ACM International Symposium on Microarchitecture, Toronto, ON, Canada, 28 October–1 November 2023. [Google Scholar] [CrossRef] [Scilit]
- Ling, H.; Huang, H.; Wang, C.; Cai, Y.; Zhang, C. GiantSan: Efficient Operation-Level Memory Sanitization with Segment Folding. ACM Trans. Comput. Syst. 2025, 2, 433–449. [Google Scholar] [CrossRef] [Scilit]
- Kim, M.; Park, J.; Cho, G.; Kim, Y.; Orosa, L.; Mutlu, O.; Kim, J. Evanesco: Architectural Support for Efficient Data Sanitization in Modern Flash-Based Storage Systems. In Proceedings of the Twenty-Fifth International Conference on Architectural Support for Programming Languages and Operating Systems, Lausanne, Switzerland, 16–20 March 2020; ASPLOS ’20; pp. 1311–1326. [Google Scholar] [CrossRef] [Scilit]


| CVE | FreeRTOS Library | Severity | Version |
|---|---|---|---|
| CVE-2018-16522 | Secure Sockets | High | Amazon FreeRTOS v1.3.2 |
| CVE-2018-16523 | FreeRTOS + TCP | High | Amazon FreeRTOS v1.3.2 |
| CVE-2018-16524 | FreeRTOS + TCP | Medium | Amazon FreeRTOS v1.3.2 |
| CVE-2018-16525 | FreeRTOS + TCP | High | Amazon FreeRTOS v1.3.2 |
| CVE-2018-16526 | FreeRTOS + TCP | High | Amazon FreeRTOS v1.3.2 |
| CVE-2018-16527 | FreeRTOS + TCP | Medium | Amazon FreeRTOS v1.3.2 |
| CVE-2018-16528 | Secure Sockets | High | Amazon FreeRTOS v1.3.2 |
| CVE-2018-16598 | FreeRTOS + TCP | Medium | Amazon FreeRTOS v1.3.2 |
| CVE-2018-16599 | FreeRTOS + TCP | Medium | Amazon FreeRTOS v1.3.2 |
| CVE-2018-16600 | FreeRTOS + TCP | Medium | Amazon FreeRTOS v1.3.2 |
| CVE-2018-16601 | FreeRTOS + TCP | High | Amazon FreeRTOS v1.3.2 |
| CVE-2018-16602 | FreeRTOS + TCP | Medium | Amazon FreeRTOS v1.3.2 |
| CVE-2018-16603 | FreeRTOS + TCP | Medium | Amazon FreeRTOS v1.3.2 |
| CVE-2019-13120 | MQTT | High | Amazon FreeRTOS v1.4.9 |
| CVE-2021-31571 | FreeRTOS Kernel | Critical | FreeRTOS Kernel v10.4.3 |
| CVE-2021-31572 | FreeRTOS Kernel | Critical | FreeRTOS Kernel v10.4.3 |
| CVE-2021-32020 | FreeRTOS Kernel | Critical | FreeRTOS Kernel v10.4.3 |
| CVE-2021-43997 | FreeRTOS Kernel | High | FreeRTOS Kernel v10.4.6 |
| and v10.4.3-LTS- Patch-2 |
| CapCause | Violation | Impact |
|---|---|---|
| 0x01 | Bound Violation | 6 |
| 0x02 | Tag Violation | 9 |
| 0x03 | Seal Violation | 8 |
| 0x04 | Type Violation | 9 |
| 0x08 | Software-defined Permission Violation | 5 |
| 0x10 | GLOBAL Violation | 7 |
| 0x11 | PERMIT_EXECUTE Violation | 7 |
| 0x12 | PERMIT_LOAD Violation | 5 |
| 0x13 | PERMIT_STORE Violation | 6 |
| 0x14 | PERMIT_LOAD_CAPABILITY | 7 |
| 0x15 | PERMIT_STORE_CAPABILITY | 7 |
| 0x16 | PERMIT_STORE_LOCAL_CAPABILITY | 7 |
| 0x18 | PERMIT_ACCESS_SYSTEM_REGISTERS | 7 |
| 0x19 | PERMIT_INVOKE Violation | 8 |
| 0x1c | PERMIT_SET_CID Violation | 9 |
Moderate impact,
Critical impact.| CapCause | Mitigation Strategy |
|---|---|
| 0x01 | Adjusting capability bounds to valid ranges to restrict access within permissible limits. |
| 0x08 | Revoking the violated permissions to ensure the task operates within allowed constraints. |
| 0x10 | Removing GLOBAL permission to restrict cross-compartment access and enforce isolation. |
| 0x11 | Revoking execute permission, allowing the task to continue without execution rights. |
| 0x12 | Restricting read access by revoking load permissions to prevent unauthorized data access. |
| 0x13 | Downgrading permissions to read-only, preventing unauthorized write operations. |
| 0x14 | Blocking capability loading to prevent unauthorized access to capabilities. |
| 0x15 | Preventing capability storage to avoid potential capability forgery or misuse. |
| 0x16 | Restricting local capability storage to maintain temporal safety and prevent misuse. |
| 0x18 | Denying system register access to protect sensitive system resources from unauthorized use. |
| CapCause | Security Consequence |
|---|---|
| 0x01 | Buffer overflows or heap exploitation (Bounds) |
| 0x02 | Using unauthorized capabilities (Tag) |
| 0x03 | Modifying sealed capabilities (Integrity) |
| 0x04 | Performing unauthorized operation (Type) |
| 0x08 | Violating software-defined permissions |
| 0x10 | Unauthorized memory access |
| 0x11 | Unauthorized code execution |
| 0x12 | Unauthorized data access |
| 0x13 | Unauthorized data modification |
| 0x14 | Unauthorized capability leakage |
| 0x15 | Privilege escalation attempts |
| 0x16 | Unauthorized capability acquisition |
| 0x18 | Unauthorized system register modification |
| 0x19 | Unauthorized capability usage |
| 0x1c | Unauthorized compartment switching |
| Metric | FreeRTOS | CHERIOT | RPA |
|---|---|---|---|
| Thread Continuation Rate | 100% | 0 | 92% |
| Violation Handling Time | 0.8 s | 0.5 s | 2.3 s |
| System Downtime | 0 s | 18.4 s | 0.9 s |
| Violation Type | CHERIoT | RPA |
|---|---|---|
| Execute Violation | × | ✓ |
| Load Violation | × | ✓ |
| Store Violation | × | ✓ |
| Seal Violation | × | ✓ |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
Share and Cite
Soltani Siapoush, M.; Alves-Foss, J. Exception-Driven Security: A Risk-Aware Permission Adjustment for High-Availability Embedded Systems. Mathematics 2025, 13, 3304. https://doi.org/10.3390/math13203304
Soltani Siapoush M, Alves-Foss J. Exception-Driven Security: A Risk-Aware Permission Adjustment for High-Availability Embedded Systems. Mathematics. 2025; 13(20):3304. https://doi.org/10.3390/math13203304
Chicago/Turabian StyleSoltani Siapoush, Mina, and Jim Alves-Foss. 2025. "Exception-Driven Security: A Risk-Aware Permission Adjustment for High-Availability Embedded Systems" Mathematics 13, no. 20: 3304. https://doi.org/10.3390/math13203304
APA StyleSoltani Siapoush, M., & Alves-Foss, J. (2025). Exception-Driven Security: A Risk-Aware Permission Adjustment for High-Availability Embedded Systems. Mathematics, 13(20), 3304. https://doi.org/10.3390/math13203304





