Ten years of hardware Trojans: a survey from the attacker's perspective

Ten years of hardware Trojans: a survey from the attacker's perspective
复制标题

DOI:
10.1049/iet-cdt.2020.0041
复制
发表时间:
2020-06
期刊:
IET Comput. Digit. Tech.
影响因子:
--
通讯作者:
Mingfu Xue;Chongyan Gu;Weiqiang Liu;Shichao Yu;Máire O’Neill
Mingfu Xue;Chongyan Gu;Weiqiang Liu;Shichao Yu;Máire O’Neill
中科院分区:
其他
文献类型:
--
作者:
Mingfu Xue;Chongyan Gu;Weiqiang Liu;Shichao Yu;Máire O’Neill

文献摘要

被引文献

相似文献

硬件木马检测技术已被广泛研究。然而,为了开发可靠有效的防御,重要的是要弄清楚硬件木马在实际场景中是如何实现的。作者试图对近十年来硬件木马的设计和实现进行回顾,并提出展望。与以往所有从防御者角度讨论木马的调查不同,作者首次从攻击者的角度研究木马,重点关注攻击者设计和实现硬件木马时的方法、能力和挑战。首先,作者从对手的方法、对手的能力以及对手在七个实际硬件木马实施场景中面临的挑战方面提出了对抗模型:内部设计团队攻击、第三方知识产权供应商攻击、计算机辅助设计工具攻击、制造阶段攻击、测试阶段攻击、分发阶段攻击和现场可编程门阵列木马攻击。其次,作者从硬件木马的攻击场景、攻击者的动机、可行性、可检测性(反检测能力)、设计者的保护和预防建议、开销分析和木马实现案例研究七个方面/指标分析了每种对抗模型下的硬件木马实现方法。最后还讨论了硬件木马攻击和防御的未来发展方向。
Hardware Trojan detection techniques have been studied extensively. However, to develop reliable and effective defenses, it is important to figure out how hardware Trojans are implemented in practical scenarios. The authors attempt to make a review of the hardware Trojan design and implementations in the last decade and also provide an outlook. Unlike all previous surveys that discuss Trojans from the defender's perspective, for the first time, the authors study the Trojans from the attacker's perspective, focusing on the attacker's methods, capabilities, and challenges when the attacker designs and implements a hardware Trojan. First, the authors present adversarial models in terms of the adversary's methods, adversary's capabilities, and adversary's challenges in seven practical hardware Trojan implementation scenarios: in-house design team attacks, third-party intellectual property vendor attacks, computer-aided design tools attacks, fabrication stage attacks, testing stage attacks, distribution stage attacks, and field-programmable gate array Trojan attacks. Second, the authors analyse the hardware Trojan implementation methods under each adversarial model in terms of seven aspects/metrics: hardware Trojan attack scenarios, the attacker's motivation, feasibility, detectability (anti-detection capability), protection and prevention suggestions for the designer, overhead analysis, and case studies of Trojan implementations. Finally, future directions on hardware Trojan attacks and defenses are also discussed.