CASPER: an efficient approach to detect anomalous code execution from unintended electronic device emissions

CASPER: an efficient approach to detect anomalous code execution from unintended electronic device emissions
复制标题

DOI:
10.1117/12.2500234
复制
发表时间:
2018-05
期刊:
--
影响因子:
--
通讯作者:
H. Agrawal;Ray S. Chen;J. Hollingsworth;Christine Hung;R. Izmailov;John Koshy;Joe Liberti;Chris Mesterharm;J. Morman;Thimios Panagos;M. Pucci;Isil Sebüktekin;Scott Alexander;Simon Tsang
H. Agrawal;Ray S. Chen;J. Hollingsworth;Christine Hung;R. Izmailov;John Koshy;Joe Liberti;Chris Mesterharm;J. Morman;Thimios Panagos;M. Pucci;Isil Sebüktekin;Scott Alexander;Simon Tsang
中科院分区:
其他
文献类型:
--
作者:
H. Agrawal;Ray S. Chen;J. Hollingsworth;Christine Hung;R. Izmailov;John Koshy;Joe Liberti;Chris Mesterharm;J. Morman;Thimios Panagos;M. Pucci;Isil Sebüktekin;Scott Alexander;Simon Tsang

文献摘要

被引文献

相似文献

CASPER系统提供了一种轻量级的、多学科的方法,通过监控非预期的电子设备排放来检测异常代码的执行。使用商用硬件和新型信号处理、机器学习和程序分析技术的组合,我们已经证明了通过分析设备RF发射来检测在距离CASPER系统12”的设备上运行的未知代码的能力。我们在传感器子系统方面的创新包括多天线处理算法,使我们能够在现实训练和监控环境中遇到背景噪声和干扰的情况下扩展范围并提取信号特征。此外,已经开发了鲁棒的特征估计方法,其允许在存在变化的时钟频率和可能从设备到设备或从训练到监视改变的其他方面的情况下检测设备操作条件。此外,频带扫描技术已被实现,以自动识别合适的频带进行监测的基础上的一组指标,包括接收功率,预期的频谱特征内容(基于环路长度和时钟频率),峰度,和模式聚类。CASPER还包括一个自动标记功能,用于发现信号处理功能,提供最大的检测信息,而无需人工干预。该系统还包括异常检测引擎的框架,目前基于n-gram、统计频率和控制流填充有三个引擎。正如我们将要描述的,这些引擎的组合减少了攻击者在试图隐藏CASPER时可以采用的方法。我们将描述CASPER的概念、所使用的组件和技术、迄今为止的结果摘要以及进一步发展的计划。CASPER是DARPA LADS计划资助的一个正在进行的研究项目。
The CASPER system offers a lightweight, multi-disciplinary approach to detect the execution of anomalous code by monitoring the unintended electronic device emissions. Using commodity hardware and a combination of novel signal processing, machine learning, and program analysis techniques, we have demonstrated the ability to detect unknown code running on a device placed 12” from the CASPER system by analyzing the devices RF emissions. Our innovations for the sensors subsystem include multi-antenna processing algorithms which allow us to extend range and extract signal features in the presence of background noise and interference encountered in realistic training and monitoring environments. In addition, robust feature estimation methods have been developed that allow detection of device operating conditions in the presence of varying clock frequency and other aspects that may change from device to device or from training to monitoring. Furthermore, a band-scan technique has been implemented to automatically identify suitable frequency bands for monitoring based on a set of metrics including received power, expected spectral feature content (based on loop length and clock frequency), kurtosis, and mode clustering. CASPER also includes an auto-labeling feature that is used to discover the signal processing features that provide the greatest information for detection without human intervention. The system additionally includes a framework for anomaly detection engines, currently populated with three engines based on n-grams, statistical frequency, and control flow. As we will describe, the combination of these engines reduces the ways in which an attacker can adapt in an attempt to hide from CASPER. We will describe the CASPER concept, components and technologies used, a summary of results to-date, and plans for further development. CASPER is an ongoing research project funded under the DARPA LADS program.