Runtime Identification of Hardware Trojans by Feature Analysis on Gate-Level Unstructured Data and Anomaly Detection

Runtime Identification of Hardware Trojans by Feature Analysis on Gate-Level Unstructured Data and Anomaly Detection
复制标题

DOI:
10.1145/3391890
复制
发表时间:
2020-05
期刊:
ACM Transactions on Design Automation of Electronic Systems (TODAES)
影响因子:
--
通讯作者:
Arunkumar Vijayan;M. Tahoori;K. Chakrabarty
Arunkumar Vijayan;M. Tahoori;K. Chakrabarty
中科院分区:
其他
文献类型:
--
作者:
Arunkumar Vijayan;M. Tahoori;K. Chakrabarty

文献摘要

被引文献

相似文献

随着芯片设计和制造工艺全球化的普及,硬件木马等恶意硬件夹杂对数字系统的安全构成了严重威胁。高级特洛伊木马可以掩盖许多架构级别的特洛伊木马签名,并适应多种检测机制。木马检测技术被认为是防止木马包含和激活的最后一道防线。在这篇文章中,我们提出了一个离线分析,选择一个子集的触发器作为代理人,并建立一个异常检测模型的基础上的活动配置文件的触发器。这些触发器受到在线监控,在线实施的异常检测模型分析触发器数据以检测任何异常特洛伊木马活动。我们的方法的有效性已经过测试的几个特洛伊木马插入设计的莱昂3处理器。通过监控少于触发器总数的0.5%,检测到特洛伊木马激活的准确性得分高于0.9(真实预测数与预测总数的比率),没有误报。
As the globalization of chip design and manufacturing process becomes popular, malicious hardware inclusions such as hardware Trojans pose a serious threat to the security of digital systems. Advanced Trojans can mask many architectural-level Trojan signatures and adapt against several detection mechanisms. Runtime Trojan detection techniques are considered as a last line of defense against Trojan inclusion and activation. In this article, we propose an offline analysis to select a subset of flip-flops as surrogates and build an anomaly detection model based on the activity profile of flip-flops. These flip-flops are monitored online, and the anomaly detection model implemented online analyzes the flip-flop data to detect any anomalous Trojan activity. The effectiveness of our approach has been tested on several Trojan-inserted designs of the Leon3 processor. Trojan activation is detected with an accuracy score of above 0.9 (ratio of the number of true predictions to total number of predictions) with no false positives by monitoring less than 0.5% of the total number of flip-flops.