Runtime Malware Detection Using Embedded Trace Buffers

Runtime Malware Detection Using Embedded Trace Buffers
复制标题

使用嵌入式跟踪缓冲区进行运行时恶意软件检测

DOI:
10.1109/tcad.2021.3052856
复制
发表时间:
2022
影响因子:
2.9
通讯作者:
R. Karri
R. Karri
中科院分区:
计算机科学3区
文献类型:
--
作者:
Rana Elnaggar;K. Basu;K. Chakrabarty;R. Karri

文献摘要

被引文献

相似文献

防病毒软件(AVS)工具用于检测系统中的恶意软件。然而,AVS容易受到攻击。恶意实体可以利用这些漏洞来破坏AVS。近来,诸如硬件性能计数器的硬件组件已经被用于恶意软件检测。在这篇文章中,我们提出了通过检查嵌入式处理器跟踪(PREEMPT)来抢占恶意软件,这是一种零开销,高精度,低延迟的技术,通过重新利用嵌入式跟踪缓冲区(ETB)来检测恶意软件,ETB是大多数现代处理器中可用的调试硬件组件。ETB用于硅后验证和调试,使我们能够控制和监控芯片的内部活动,而不是输入/输出引脚提供的活动。PREEMPT将这些硬件级观察与基于机器学习的分类器相结合,以在恶意软件造成损害之前先发制人。重用ETB进行恶意软件检测的好处包括增强了对攻击的鲁棒性,并且没有性能损失。PREEMPT可以检测运行Linux操作系统的OpenSSL T1核心上的恶意软件,F1得分为96.6%。
Anti-virus software (AVS) tools are used to detect malware in a system. However, AVS are vulnerable to attacks. A malicious entity can exploit these vulnerabilities to subvert the AVS. Recently, hardware components such as hardware performance counters have been used for malware detection. In this article, we propose preempts malware by examining embedded processor traces (PREEMPT), a zero overhead, high-accuracy, low-latency technique to detect malware by repurposing embedded trace buffer (ETB), a debug hardware component available in most modern processors. The ETB is used for postsilicon validation and debug and allows us to control and monitor the internal activities of a chip, beyond what is provided by the input/output pins. PREEMPT combines these hardware-level observations with machine learning-based classifiers to preempt malware before it causes damage. The benefits of reusing ETB for malware detection include the increased robustness against attacks and no performance penalties. PREEMPT can detect malware on an OpenSPARC T1 core running Linux operating system with a F1-score of 96.6%.