Think Smart, Play Dumb: Analyzing Deception in Hardware Trojan Detection Using Game Theory

Think Smart, Play Dumb: Analyzing Deception in Hardware Trojan Detection Using Game Theory
复制标题

DOI:
10.1109/cybersecurity49315.2020.9138897
复制
发表时间:
2020-06
期刊:
2020 International Conference on Cyber Security and Protection of Digital Services (Cyber Security)
影响因子:
--
通讯作者:
Tapadhir Das;Abdelrahman Eldosouky;S. Sengupta
Tapadhir Das;Abdelrahman Eldosouky;S. Sengupta
中科院分区:
其他
文献类型:
--
作者:
Tapadhir Das;Abdelrahman Eldosouky;S. Sengupta

文献摘要

相似文献

近年来,集成电路(ic)在各个行业中变得越来越重要,其安全性得到了更大的重视,特别是在供应链中。预算限制迫使IC设计人员将生产外包给第三方公司。当设计人员收回制造的ic时,必须测试硬件木马(HT)等潜在威胁。本文引入了一种新的多层次博弈论框架来分析恶意集成电路制造商与测试者之间的相互作用。特别是,利用前景理论(PT)将博弈制定为非合作、零和、重复的博弈,该理论捕捉了不同参与者在不确定性下的理性。重复的游戏被分成学习阶段,在这个阶段,防御者学习攻击者的倾向,以及实际的游戏阶段,在这个阶段,学习将被使用。实验表明,攻击者在学习阶段(欺骗)有很大的动机通过“装聋作哑”来欺骗防御者的实际合理性。这个场景是使用超博弈理论来模拟攻击者对游戏的看法。以效用增益最大化为目标,解析推导出攻击者的最佳欺骗合理性。对于防御方,提出了第一步欺骗缓解过程来阻止欺骗的影响。仿真结果表明,攻击者可以在不被检测到的情况下成功地将HTs插入到制造的集成电路中,从而从中获利。
In recent years, integrated circuits (ICs) have become significant for various industries and their security has been given greater priority, specifically in the supply chain. Budgetary constraints have compelled IC designers to offshore manufacturing to third-party companies. When the designer gets the manufactured ICs back, it is imperative to test for potential threats like hardware trojans (HT). In this paper, a novel multi-level game-theoretic framework is introduced to analyze the interactions between a malicious IC manufacturer and the tester. In particular, the game is formulated as a non-cooperative, zero-sum, repeated game using prospect theory (PT) that captures different players’ rationalities under uncertainty. The repeated game is separated into a learning stage, in which the defender learns about the attacker’s tendencies, and an actual game stage, where this learning is used. Experiments show great incentive for the attacker to deceive the defender about their actual rationality by "playing dumb" in the learning stage (deception). This scenario is captured using hypergame theory to model the attacker’s view of the game. The optimal deception rationality of the attacker is analytically derived to maximize utility gain. For the defender, a first-step deception mitigation process is proposed to thwart the effects of deception. Simulation results show that the attacker can profit from the deception as it can successfully insert HTs in the manufactured ICs without being detected.