TruDetect: Trustworthy Deep-Learning based Hardware Trojan Detection
TruDetect: Trustworthy Deep-Learning based Hardware Trojan Detection
批准号:
EP/X036960/1
负责人:
Máire O'Neill
金额:
$112.27万
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2023
资助国家:
英国
项目状态:
未结题
起止时间:
2023 至 --
中文摘要
现代半导体供应链使用海外代工厂、第三方知识产权和第三方测试设施。然而,由于有如此多不同的不受信任的实体,这种设计和制造外包使硅芯片暴露在一系列基于硬件的安全威胁之下,例如假冒、IP盗版、逆向工程和硬件木马(HT)。硬件木马是对电路进行的恶意修改,目的是控制、修改、禁用、监视或影响电路的运行。尽管在实践中没有发现任何关于山寨产品的公开报道,但在2020年,网络安全公司F-Secure发布了一份关于他们对一对假冒思科Catalyst 2960-X系列交换机的调查报告。虽然这些设备没有后门功能,但它们确实采取了一些措施来绕过对系统组件进行身份验证的过程,F-Secure表示,有动机的攻击者会使用相同的方法向后门公司插入硬件木马。此类硬件威胁是安全关键型和嵌入式系统应用的主要安全威胁,例如医疗、汽车或运输部门。由于这一秘密行业的性质,很难确定问题的真正规模。然而,近年来,半导体供应链的主权和网络安全已成为许多国家的重大关切。最近发布的《欧盟网络弹性法案》(2022年9月)概述了含有数字元素的产品的基本网络安全要求,并指出此类产品“应在没有任何已知可利用漏洞的情况下交付”。此外,2022年国家网络战略概述了需要“确保尽可能在设计、开发和部署下一代互联技术时考虑到安全性和弹性,并……采用“设计安全”的方法。TruDetect项目的总体目标是开发一个可信赖的基于dll的高温检测系统,该系统可以轻松集成到EDA工具中的安全验证框架中。这将包括设计新的对策,以确保基于DL的HT检测系统对对抗性HT的可靠性,并使用可解释的人工智能来提供DL系统行为的全面分析。
英文摘要
The modern semiconductor supply chain uses overseas foundries, third-party IP and third-party test facilities. However, with so many different untrusted entities, this design and fabrication outsourcing has exposed silicon chips to a range of hardware-based security threats such as counterfeiting, IP piracy, reverse engineering and hardware Trojans (HT).A hardware Trojan is a malicious modification of a circuit in order to control, modify, disable, monitor or affect the operation of the circuit. Although there have been no public reports of HTs detected in practice, in 2020, the cybersecurity company F-Secure published a report on their investigation into a pair of counterfeit Cisco Catalyst 2960-X series switches . While these devices did not have back-door functionality, they did employ measures to bypass processes that authenticate system components and F-Secure stated that motivated attackers use the same approach to insert hardware trojans to stealthily backdoor companies.Such hardware threats are major security threats for safety-critical and embedded systems applications, for e.g in the medical, automotive or transport sectors. Due to the nature of this clandestine industry, it is very difficult to ascertain the true scale of the problem. However, in recent years both the sovereignty and cyber security of the semiconductor supply chain have become significant concerns for many countries.The recently published EU Cyber Resilience Act (September 2022) outlines essential cybersecurity requirements for products with digital elements and states that such produced ''shall be delivered without any known exploitable vulnerabilities'. In addition, the 2022 National Cyber Strategy 2022 outlines the need to 'ensure that wherever possible the next generation of connected technologies are designed, developed and deployed with security and resilience in mind and ... embrace a 'secure by design' approach'.The overall goal of the TruDetect project is to develop a trustworthy DL-based HT detection system that can be easily integrated into a security verification framework in EDA tools. This will include the design of novel countermeasures that ensure trustworthiness of the DL-based HT detection system against adversarial HTs and the use of Explainable AI to offer a comprehensive analysis of the DL system behaviour.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Centre for Secure Information Technologies (CSIT) - Phase 3
-
批准号:EP/X022323/1
-
项目类别:Research Grant
-
资助金额:$539.59万
-
财政年份:2022
-
负责人:Máire O'Neill
-
依托单位:
SIPP - Secure IoT Processor Platform with Remote Attestation
-
批准号:EP/S030867/1
-
项目类别:Research Grant
-
资助金额:$164.99万
-
财政年份:2019
-
负责人:Máire O'Neill
-
依托单位:
DeepSecurity - Applying Deep Learning to Hardware Security
-
批准号:EP/R011494/1
-
项目类别:Research Grant
-
资助金额:$97.58万
-
财政年份:2017
-
负责人:Máire O'Neill
-
依托单位:
Next-Generation Data Security Architectures
-
批准号:EP/G007586/1
-
项目类别:Fellowship
-
资助金额:$184.8万
-
财政年份:2008
-
负责人:Máire O'Neill
-
依托单位:
海外基金