REMOTE: Robust External Malware Detection Framework by Using Electromagnetic Signals

REMOTE: Robust External Malware Detection Framework by Using Electromagnetic Signals
复制标题

DOI:
10.1109/tc.2019.2945767
复制
发表时间:
2020-03
影响因子:
3.7
通讯作者:
Nader Sehatbakhsh;A. Nazari;Monjur Alam;Frank T. Werner;Yuanda Zhu;A. Zajić;Milos Prvulović
Nader Sehatbakhsh;A. Nazari;Monjur Alam;Frank T. Werner;Yuanda Zhu;A. Zajić;Milos Prvulović
中科院分区:
计算机科学2区
文献类型:
--
作者:
Nader Sehatbakhsh;A. Nazari;Monjur Alam;Frank T. Werner;Yuanda Zhu;A. Zajić;Milos Prvulović

文献摘要

被引文献

相似文献

网络物理系统(CPS)正在控制我们物理世界的许多关键和敏感方面,同时不断暴露于潜在的网络攻击中。这些系统通常具有有限的性能,内存和能量储备,这限制了它们运行现有的高级恶意软件保护的能力,进而使它们确保它们非常具有挑战性。为了解决这些问题,本文提出了一个新的健壮框架,以实时观察电子计算设备(例如微处理器)在实时运行已知应用程序的外部观察电磁(EM)信号,并实时使用电子计算设备(例如微处理器)低检测延迟,并且没有任何对恶意软件的先验知识。遥控器不需要任何资源或基础架构或对受监视系统本身的任何修改,这使得远程特别适合在资源受限设备上检测恶意软件,例如嵌入式设备,CPSS和物联网和物联网(IoT)设备(IOT)设备的硬件硬件和能源可能受到限制。为了在现实世界中演示遥控器的可用性,我们将两个现实世界程序(一个嵌入式医疗设备和一个工业PID控制器)移植,每个程序都具有有意义的攻击(代码恢复和一个代码注射攻击),以四个不同的硬件平台。我们还向基于壳牌的DDOS和勒索软件攻击端口到嵌入式系统上的五个不同的标准应用程序。为了进一步证明遥控器对商业CP的适用性,我们使用遥控器监视机器人臂。我们在所有这些不同的硬件平台上的结果表明,对于对每个平台的所有攻击,远程都成功地检测了攻击的每个实例,并且具有0.1%的误报。我们还系统地评估了遥控器到中断和其他系统活动的鲁棒性,以发出同一设备设计的不同物理实例之间的差异,随着时间的推移以及塑料外壳和附近的电子设备的变化。该评估包括数百种测量值,并表明在所有这些条件下,遥控器可实现出色的准确性($ 0.1%的假阳性和$> $> $> $> $> $> 99.9%)。我们还将远程与先前的工作Eddie [1]和综合征[2]进行了比较,并证明了这些先前的工作在这些变化下无法实现高精度。
Cyber-physical systems (CPS) are controlling many critical and sensitive aspects of our physical world while being continuously exposed to potential cyber-attacks. These systems typically have limited performance, memory, and energy reserves, which limits their ability to run existing advanced malware protection, and that, in turn, makes securing them very challenging. To tackle these problems, this paper proposes, Remote, a new robust framework to detect malware by externally observing Electromagnetic (EM) signals emitted by an electronic computing device (e.g., a microprocessor) while running a known application, in real-time and with a low detection latency, and without any a priori knowledge of the malware. Remote does not require any resources or infrastructure on, or any modifications to, the monitored system itself, which makes Remote especially suitable for malware detection on resource-constrained devices such as embedded devices, CPSs, and Internet of Things (IoT) devices where hardware and energy resources may be limited. To demonstrate the usability of Remote in real-world scenarios, we port two real-world programs (an embedded medical device and an industrial PID controller), each with a meaningful attack (a code-reuse and a code-injection attack), to four different hardware platforms. We also port shellcode-based DDoS and Ransomware attacks to five different standard applications on an embedded system. To further demonstrate the applicability of Remote to commercial CPS, we use Remote to monitor a Robotic Arm. Our results on all these different hardware platforms show that, for all attacks on each of the platforms, Remote successfully detects each instance of an attack and has $0.1 percent false positives. We also systematically evaluate the robustness of Remote to interrupts and other system activity, to signal variation among different physical instances of the same device design, to changes over time, and to plastic enclosures and nearby electronic devices. This evaluation includes hundreds of measurements and shows that Remote achieves excellent accuracy ($0.1 percent false positive and $>$>99.9 percent true positive rates) under all these conditions. We also compare Remote to prior work EDDIE [1] and SYNDROME [2], and demonstrate that these prior work are unable to achieve high accuracy under these variations.