A prototype implementation and evaluation of the malware detection mechanism for IoT devices using the processor information

A prototype implementation and evaluation of the malware detection mechanism for IoT devices using the processor information
复制标题

DOI:
10.1007/s10207-019-00437-y
复制
发表时间:
2020-02-01
影响因子:
3.2
通讯作者:
Ohmura, Ren
Ohmura, Ren
中科院分区:
计算机科学4区
文献类型:
--
作者:
Takase, Hayate;Kobayashi, Ryotaro;Ohmura, Ren

文献摘要

被引文献

相似文献

由于物联网(IoT)设备的普及,无数种类的设备已经连接到互联网。虽然包括家电在内的各种设备通过互联网运行,但由于存在漏洞,针对许多物联网设备的攻击正在增加。此外,还存在一个问题,即很难将安全机制作为软件引入,因为它们的硬件资源很少。因此,需要一种不消耗CPU、内存等硬件资源的安全机制。我们提出了一种利用从处理器中提取值的恶意软件检测机制。我们的目标是利用处理器信息将恶意软件检测机制卸载到硬件上,并抑制硬件资源的消耗。在本文中,我们使用虚拟机QEMU实现了我们提出的机制的原型。我们证明了我们提出的机制可以利用处理器信息对恶意软件或良性程序进行分类,也可以检测属于同一家族的恶意软件变体。
Due to the popularization of Internet of Things (IoT) devices, numerous and varied devices have been connected to the Internet. While various devices including home appliances operate via the Internet, attacks targeting many IoT devices are increasing because the vulnerabilities exist in them. Furthermore, there is a problem that introducing a security mechanism as software is difficult because they have few hardware resources. Therefore, a security mechanism which does not consume hardware resources such as CPU and memory is required. We propose a malware detection mechanism using values extracted from the processor. We aim to offload the malware detection mechanism to hardware by using the processor information and aim to suppress the consumption of hardware resources. In this paper, we implemented a prototype of our proposed mechanism using QEMU, which is a virtual machine. We show that our proposed mechanism can classify malware or benign programs by using the processor information as well as detect malware variant belonging to the same family.