EAGER: SARE: Detecting Zero-Day Side-channel Attacks in Sensor Rich Cyber-Physical Systems
EAGER: SARE: Detecting Zero-Day Side-channel Attacks in Sensor Rich Cyber-Physical Systems
批准号:
2028782
负责人:
Fadi Kurdahi
金额:
$30.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-10-01 至 2023-09-30
中文摘要
本项目介绍了一种使用自动化流程检测富含传感器的网络物理系统上的侧信道攻击的方法。该方法几乎能够立即且高精度地识别异常行为,这些异常行为表明可能存在危险的情况,这些异常行为要么是已知的特征,要么是在部署前测试期间从未遇到过的。这个项目的目标是有一个原型来展示它为转换到实践和最终部署所做的准备。解决三种类型的威胁:(1)利用零日攻击和复杂的逃避技术的故意入侵;(2)内部威胁:内部人员通过欺骗或不欺骗用户身份来滥用特权;(3)在安全关键系统的预部署测试期间从未遇到异常行为,可能表明故障。这些异常包括由于错误造成的意外或无意故障,以及导致执行紧急操作的物理侧通道攻击。在许多对安全至关重要的网络物理系统中,异常是特别危险的。例如,针对汽车的攻击,如防抱死制动系统(ABS)传感器欺骗、无线指令注入和发动机控制单元(ECU)渗透等,已被证明最终会导致车祸或严重偏离道路。当涉及到安全关键型和任务关键型网络物理系统时,研究的重要性再怎么强调也不为过,这些系统越来越依赖于人工智能和机器学习来进行决策、态势感知和一般推理。深度学习算法和模型的可解释性难题,加上需要对整个系统的安全性和安全性进行认证,表明在操作过程中对这两个标准(安全性和安全性)进行持续检查的重要性,不仅可以防止意外行为,还可以防止系统硬件(包括传感器/执行器)中的潜在错误和故障。该研究将创建一个框架,允许网络物理系统通过检测和诊断不安全和不安全异常情况的能力获得安全性认证。该研究结合了用于嵌入式系统的可扩展运行时验证(RV)框架和用于异常检测(AD)的Paraminer规范挖掘工具。这种RV+AD方法的一个关键特性是,不仅可以使用与CPU执行相关的跟踪,还可以使用其他系统组件(如存储器、总线、传感器和执行器)监视属性。这种跨网络和物理状态的可观察性增加了处理难以检测或阻止的物理侧信道攻击的重要能力。这可以通过将CPU上的程序执行和传感器数据的跟踪相关联来实现。例如,在电源侧信道攻击中,当前传感器数据可以与CPU上运行的关键高级加密标准(AES)加密算法的执行相关联,以检测潜在漏洞的周期,并采取混淆措施来阻止此类攻击。这个项目中的方法是基于硬件的,而之前的最先进的方法是基于软件的。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
This project introduces a method using an automated flow to detect side channel attacks over sensor-rich cyber-physical systems. The approach has the ability to identify, almost instantly and with high precision, anomalous behaviors indicative of possibly hazardous situations with either a known signature or never encountered during pre-deployment testing. The goal of this project is to have a prototype demonstrating its readiness for transition to practice and eventual deployment. Three types of threats are tackled: (1) Deliberate intrusions employing zero-day attacks and sophisticated evasion techniques; (2) Insider threats: abuse of privileges by insiders with or without spoofing of user identities; (3) Anomalous behaviors never encountered during pre-deployment testing of safety-critical systems and possibly indicative of malfunctioning. These anomalies include accidental or inadvertent failures due to bugs as well as physical side channel attacks that gives rise to execution of emergency actions. Anomalies in many safety-critical cyber-physical systems are particularly dangerous. For example, attacks against a car such as antilock-braking system (ABS) sensor spoofing, wireless command injection, and engine control unit (ECU) infiltration have been demonstrated, leading ultimately to a car crash or significant drift off the road. The importance of the research cannot be overstated when it comes to safety-critical and mission-critical cyber-physical systems that are increasingly relying on artificial intelligence and machine learning for decision making, situational awareness, and general reasoning. The explainability conundrum of deep learning algorithms and models coupled with the need to certify the overall system for safety and security points to the criticality of imposing continuous checks on these two criteria (safety and security) during operation to safeguard not only against unanticipated behavior but also the potential bugs and failures in system hardware including sensors/actuators. The research will create a framework allowing cyber-physical systems to be certified for safety and security through the ability to detect and diagnose unsafe and insecure anomalous situations.The research combines a scalable Runtime Verification (RV) framework intended for embedded systems and a Paraminer specification mining tool for Anomaly Detection (AD). A critical feature in this RV+AD approach is the ability to monitor properties using not only traces relevant to CPU execution, but also other system components such as memories, buses, sensors, and actuators. This observability across both the cyber and physical states adds significant capabilities to deal with physical side channel attacks which are extremely hard to detect or thwart. This can be achieved by correlating traces from both program execution on the CPU(s) and sensor data. In a power side channel attack, for example, the current sensor data can be correlated with execution of critical advanced encryption standard (AES) encryption algorithms running on the CPU to detect periods of potential vulnerability, and engage obfuscation measures to thwart such attacks. The approach in this project is hardware-based whereas the prior state-of-the-art approaches have been software-based.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
An Accurate Non-accelerometer-based PPG Motion Artifact Removal Technique using CycleGAN
使用 CycleGAN 的精确非基于加速度计的 PPG 运动伪影去除技术
DOI:
10.1145/3563949
发表时间:
2022
期刊:
ACM Transactions on Computing for Healthcare
影响因子:
--
作者:
[Zargari, Amir Hosein, Aqajari, Seyed Amir, Khodabandeh, Hadi, Rahmani, Amir M., Kurdahi, Fadi]
通讯作者:
Kurdahi, Fadi
SAFER: Safety Assurances For Emergent Behavior
更安全:紧急行为的安全保证
DOI:
10.1109/mdat.2023.3324887
发表时间:
2023
期刊:
IEEE Design & Test
影响因子:
2
作者:
[De Melo, Caio Batista, Ashrafiamiri, Marzieh, Seo, Minjun, Kurdahi, Fadi, Dutt, Nikil]
通讯作者:
Dutt, Nikil
FPGA Implementation of Associative Processors
关联处理器的 FPGA 实现
DOI:
10.1109/tcsii.2023.3261702
发表时间:
2023
期刊:
IEEE Transactions on Circuits and Systems II: Express Briefs
影响因子:
--
作者:
[Tian, Hongzheng, Fouda, Mohammed E., Seo, Minjun, Kurdahi, F. J.]
通讯作者:
Kurdahi, F. J.
DOI:
10.23919/date56975.2023.10137006
发表时间:
2023-04
期刊:
2023 Design, Automation & Test in Europe Conference & Exhibition (DATE)
影响因子:
--
作者:
[Nora Sperling;Alex Bendrick;Dominik Stöhrmann;Rolf Ernst;Bryan Donyanavard;F. Maurer;Oliver Lenke;A. Surhonne;A. Herkersdorf;Walaa Amer;Caio Batista de Melo;Ping-Xiang Chen;Quang Anh Hoang;Rachid Karami;Biswadip Maity;Paul Nikolian;Mariam Rakka;Dongjoo Seo;Saehanseul Yi;Minjun Seo;N. Dutt;Fadi J. Kurdahi]
通讯作者:
Nora Sperling;Alex Bendrick;Dominik Stöhrmann;Rolf Ernst;Bryan Donyanavard;F. Maurer;Oliver Lenke;A. Surhonne;A. Herkersdorf;Walaa Amer;Caio Batista de Melo;Ping-Xiang Chen;Quang Anh Hoang;Rachid Karami;Biswadip Maity;Paul Nikolian;Mariam Rakka;Dongjoo Seo;Saehanseul Yi;Minjun Seo;N. Dutt;Fadi J. Kurdahi
DT2CAM: A Decision Tree to Content Addressable Memory Framework
DT2CAM:内容可寻址内存框架的决策树
DOI:
10.1109/tetc.2023.3261748
发表时间:
2023
期刊:
IEEE Transactions on Emerging Topics in Computing
影响因子:
5.9
作者:
[Rakka, Mariam, Fouda, Mohammed E., Kanj, Rouwaida, Kurdahi, Fadi]
通讯作者:
Kurdahi, Fadi
共 6 条
Collaborative Research: EAGER: IC-Cloak: Integrated Circuit Cloaking against Reverse Engineering
-
批准号:2213486
-
项目类别:Standard Grant
-
资助金额:$10.0万
-
财政年份:2022
-
负责人:Fadi Kurdahi
-
依托单位:
Dynamic Full-Duplex single-channel wireless communication systems
-
批准号:1710746
-
项目类别:Standard Grant
-
资助金额:$33.0万
-
财政年份:2017
-
负责人:Fadi Kurdahi
-
依托单位:
ITR: Synthesis of Adaptive Mission-Specific Processors
-
批准号:0083080
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2000
-
负责人:Fadi Kurdahi
-
依托单位:
RIA: System-Level Partitioning of VLSI Circuits Using DesignEvaluators
-
批准号:8909677
-
项目类别:Standard Grant
-
资助金额:$7.77万
-
财政年份:1989
-
负责人:Fadi Kurdahi
-
依托单位:
海外基金