A practical application of game theory to optimize selection of hardware Trojan detection strategies

A practical application of game theory to optimize selection of hardware Trojan detection strategies
复制标题

博弈论优化硬件木马检测策略选择的实际应用

DOI:
10.1007/s41635-019-00089-3
复制
发表时间:
2019
期刊:
Journal of Hardware and Systems Security
影响因子:
--
通讯作者:
P. Athanas
P. Athanas
中科院分区:
--
文献类型:
--
作者:
Jonathan Graf;Whitney Batchelor;S. Harper;Ryan Marlow;E. Carlisle;P. Athanas

文献摘要

被引文献

相似文献

已经开发了各种各样的硬件特洛伊木马对策,但很少有工作要做,以确定哪些是最佳的任何给定的设计。为了解决这个问题,我们不仅考虑与对策的性能相关的度量,而且考虑对手的目标可能采取的行动。特洛伊木马是由对手插入以达到目的,因此必须考虑和量化这些目标,以预测这些行动。这里提出的模型建立在一个安全的经济方法,模型的背景下,从经验得出的对策有效性指标的对手和防御者的动机和目标。该方法支持形成一个两个球员的战略游戏,以确定最佳的战略选择,为双方的对手和后卫。一个游戏可以在各种环境下进行,包括考虑整个设计生命周期或仅考虑产品开发中的一个步骤。作为这种方法的实用性的演示,我们提出了一个实验,从一组对策(防御者策略),当测试对木马的分类(对手策略)的功效指标。我们进一步提出了一个软件框架,GameRunner,自动化不仅解决了游戏,但也数学和图形探索的“如果”的情况下,游戏。GameRunner还可以发出“处方”,这是一组命令,允许防御者自动将最佳防御策略应用于他们关注的电路。最后,我们包括正在进行的工作,包括额外的软件工具,一个更先进的实验框架,和非理性模型的应用,以考虑球员谁作出亚理性的决定进行讨论。
A wide variety of Hardware Trojan countermeasures have been developed, but less work has been done to determine which are optimal for any given design. To address this, we consider not only metrics related to the performance of the countermeasure, but also the likely action of an adversary given their goals. Trojans are inserted by an adversary to accomplish an end, so these goals must be considered and quantified in order to predict these actions. The model presented here builds upon a security economic approach that models the adversary and defender motives and goals in the context of empirically derived countermeasure efficacy metrics. The approach supports formation of a two-player strategic game to determine optimal strategy selection for both adversary and defender. A game may be played in a variety of contexts, including consideration of the entire design lifecycle or only a step in product development. As a demonstration of the practicality of this approach, we present an experiment that derives efficacy metrics from a set of countermeasures (defender strategies) when tested against a taxonomy of Trojans (adversary strategies). We further present a software framework, GameRunner, that automates not only the solution to the game but also mathematical and graphical exploration of “what if” scenarios in the context of the game. GameRunner can also issue “prescriptions,” a set of commands that allows the defender to automate the application of the optimal defender strategy to their circuit of concern. Finally, we include a discussion of ongoing work to include additional software tools, a more advanced experimental framework, and the application of irrationality models to account for players who make subrational decisions.