Enhancing Hardware Malware Detectors’ Security through Voltage Over-scaling

Enhancing Hardware Malware Detectors’ Security through Voltage Over-scaling
复制标题

通过电压超标增强硬件恶意软件检测器的安全性

DOI:
--
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
Khaled N. Khasawneh
Khaled N. Khasawneh
中科院分区:
--
文献类型:
--
作者:
Md. Shohidul Islam;Ihsen Alouani;Khaled N. Khasawneh

文献摘要

被引文献

相似文献

计算系统受到越来越有动机和复杂的对手的持续攻击。这些攻击者利用漏洞危害系统并部署恶意软件。尽管人们继续努力提高系统抵御攻击的能力,但可利用的漏洞数量惊人。虽然防止危害是困难的,基于签名的静态分析技术可以很容易地绕过使用变形/多态恶意软件或零日漏洞,因为他们的签名还没有遇到。另一方面,动态检测技术可以检测看不见的签名,因为它们监视程序的行为。然而,由于资源有限,连续动态监测的复杂性和困难性传统上限制了其使用。在此背景下,一些研究提出使用硬件恶意软件检测器(HMD),通过硬件支持实现持续动态监控的资源效率。具体来说,HMD是机器学习分类器,其使用低级硬件特征(诸如指令跟踪、存储器访问模式等)并将恶意软件分类为计算异常。HMD可以提供显著的优势来防御恶意软件攻击,因为它们可以“始终在线”,对性能的影响很小甚至没有。看来业界也开始对使用HMD表现出兴趣;高通的SnapDragon处理器似乎正在使用硬件功能来检测恶意软件,但技术细节尚未公布[4]。由于HMD显示出潜在的防御有效性,因此很自然地期望攻击者试图找到自适应的方法来逃避检测。结果表明,攻击者可以调整恶意软件以继续运行,同时避免HMD的检测[3]。我们利用近似计算(AC)来解决防御HMD对抗规避恶意软件的挑战。特别是,我们提出了V-HMD,这是一种使用电压过缩放(VOS)用于规避弹性目的的HMD;它在推理过程中在HMD的模型中引入随机计算,从而使V-HMD对对抗性规避攻击具有弹性。
Computing systems are under continuous attacks by increasingly motivated and sophisticated adversaries. These attackers exploit vulnerabilities to compromise systems and deploy malware. Although significant effort continues to be directed at making systems more resilient to attacks, the number of exploitable vulnerabilities is overwhelming. While preventing compromise is difficult, signature based static analysis techniques can be easily bypassed using metamorphic/polymorphic malware or zero-day exploits since their signatures have not yet been encountered. On the other hand, dynamic detection techniques can detect unseen signatures since they monitor the behavior of the program. However, the complexity and difficulty of continuous dynamic monitoring have traditionally limited its use due to constrained resources. Against this backdrop, several research studies proposed using Hardware Malware Detectors (HMDs) to make the continuous dynamic monitoring resource-efficient through hardware support. Specifically, HMDs are machine learning classifiers that use low-level hardware features such as instructions traces, memory access patterns, etc. and classify malware as a computational anomaly. HMDs can offer a significant advantage to defend against malware attacks because they can be ‘always on’ with small-to-no impact on performance. It appears that the industry started to show interest in using HMDs too; SnapDragon processor from Qualcomm appears to be using hardware features to detect malware, but the technical details are not published [4]. As HMDs showed potential defense effectiveness, it is natural to expect that attackers attempt to find adaptive ways to evade detection. As a consequence, it was shown that attackers can adapt malware to continue to operate while avoiding detection by HMDs [3]. We address the challenge of defending HMDs against evasive malware by utilizing approximate computing (AC). In particular, we propose V-HMDs, which are HMDs that uses voltage over-scaling (VOS) for evasion resilience purpose; it induces stochastic computations in HMD’s model during inference, resulting in V-HMDs that are resilient to adversarial evasion attack.