Program profiling based on Markov models and EM emanations

Program profiling based on Markov models and EM emanations
复制标题

基于马尔可夫模型和电磁发射的程序分析

DOI:
--
复制
发表时间:
2020
期刊:
Defense + Commercial Sensing
影响因子:
--
通讯作者:
A. Zajić
A. Zajić
中科院分区:
--
文献类型:
--
作者:
B. Yilmaz;E. Ugurlu;Frank T. Werner;Milos Prvulović;A. Zajić

文献摘要

被引文献

相似文献

作为代码优化和性能分析的基本方法之一,分析软件活动可以提供有关恶意软件是否存在、代码执行问题等的信息。在本文中,我们提出了一种无需开销即可分析系统的方法。该方法在执行程序时利用电磁 (EM) 发射,并通过构建马尔可夫模型来利用其流程图。模型的状态被认为是程序的重度执行块(称为热路径),并且只有存在能够在没有任何中间状态的情况下执行相应状态的分支操作,才可能在任意两个状态之间进行转换。为了识别程序的状态,我们使用监督学习方法。为此,我们首先收集每个状态的信号,提取特征并生成字典。这些功能被视为程序执行时激活的频率。这里的假设是存在至少一个仅针对一种独特状态有效的独特频率分量。此外,为了降低设备其他部分发出的中断和其他信号的影响,并获得具有高信噪比 (SNR) 的信号,我们对短时傅立叶变换 (STFT) 的输出进行平均。提取特征后,我们应用主成分分析(PCA)进行降维,这有助于实时监控系统。最后,我们描述了实验设置并展示了结果,以证明所提出的方法可以高精度地检测恶意软件活动。
As one of the fundamental approaches for code optimization and performance analysis, profiling software activities can provide information on the existence of malware, code execution problems, etc. In this paper, we propose a methodology to profile a system with no overhead. The approach leverages electromagnetic (EM) emanations while executing a program, and exploits its flow diagram by constructing a Markov model. The states of the model are considered as the heavily executed blocks (called hot paths) of the program, and the transition between any two states is possible only if there exists a branching operation which enables execution of corresponding states without any intermediate state. To identify the state of the program, we utilize a supervised learning method. To do so, we first collect signals for each state, extract features, and generate a dictionary. The features are considered as the activated frequencies when the program is executed. The assumption here is that there exists at least one unique frequency component that is only active for one unique state. Moreover, to degrade the e↵ect of interruptions and other signals emanated from other parts of the device, and to obtain signals with high Signal-to-Noise Ratio (SNR), we average the output of Short-Time Fourier Transform (STFT). After extracting features, we apply Principle Component Analysis (PCA) for dimension reduction which helps monitoring systems in real time. Finally, we describe experimental setup and show results to demonstrate that the proposed methodology can detect malware activity with high accuracy.