PREEMPT: PReempting Malware by Examining Embedded Processor Traces

PREEMPT: PReempting Malware by Examining Embedded Processor Traces
复制标题

PREEMPT:通过检查嵌入式处理器跟踪来抢占恶意软件

DOI:
10.1145/3316781.3317883
复制
发表时间:
2019
期刊:
2019 56th ACM/IEEE Design Automation Conference (DAC)
影响因子:
--
通讯作者:
R. Karri
R. Karri
中科院分区:
--
文献类型:
--
作者:
K. Basu;Rana Elnaggar;K. Chakrabarty;R. Karri

文献摘要

被引文献

相似文献

反病毒软件(AVS)工具用于检测系统中的恶意软件。然而,基于软件的AVS很容易受到攻击。恶意实体可以利用这些漏洞来颠覆AVS。最近,诸如硬件性能计数器(HPC)等硬件组件已被用于恶意软件检测。在本文中,我们提出了Preempt,一种零开销、高精度和低延迟的恶意软件检测技术,它通过重新利用嵌入式跟踪缓冲区(ETB)来检测恶意软件,ETB是大多数现代处理器中提供的调试硬件组件。ETB用于芯片后验证和调试,允许我们控制和监控芯片的内部活动,而不是输入/输出引脚所能提供的功能。Preempt将这些硬件级别的观察与基于机器学习的分类器相结合,在恶意软件可能造成破坏之前先发制人。重复使用ETB进行恶意软件检测有很多好处。与软件相比,入侵硬件比较困难,因此Preempt比AVS更能抵御攻击。抢占不会导致性能损失。最后,Preempt具有94%的高真阳性值,并保持2%的低假阳性值。
Anti-virus software (AVS) tools are used to detect Malware in a system. However, software-based AVS are vulnerable to attacks. A malicious entity can exploit these vulnerabilities to subvert the AVS. Recently, hardware components such as Hardware Performance Counters (HPC) have been used for Malware detection. In this paper, we propose PREEMPT, a zero overhead, high-accuracy and low-latency technique to detect Malware by re-purposing the embedded trace buffer (ETB), a debug hardware component available in most modern processors. The ETB is used for post-silicon validation and debug and allows us to control and monitor the internal activities of a chip, beyond what is provided by the Input/Output pins. PREEMPT combines these hardware-level observations with machine learning-based classifiers to preempt Malware before it can cause damage. There are many benefits of re-using the ETB for Malware detection. It is difficult to hack into hardware compared to software, and hence, PREEMPT is more robust against attacks than AVS. PREEMPT does not incur performance penalties. Finally, PREEMPT has a high True Positive value of 94% and maintains a low False Positive value of 2%.