首页> 外文会议>Annual IEEE/IFIP International Conference on Dependable Systems and Networks >POWERALERT: Integrity Checking Using Power Measurement and a Game-Theoretic Strategy
【24h】

POWERALERT: Integrity Checking Using Power Measurement and a Game-Theoretic Strategy

机译:Poweralert:完整性检查电力测量和游戏 - 理论策略

获取原文

摘要

We propose POWERALERT, an efficient external integrity checker for untrusted hosts. Current attestation systems suffer from shortcomings, including requiring a complete checksum of the code segment, from being static, use of timing information sourced from the untrusted machine, or using imprecise timing information such as network round-trip time. We address those shortcomings by (1) using power measurements from the host to ensure that the checking code is executed and (2) checking a subset of the kernel space over an extended period. We compare the power measurement against a learned power model of the execution of the machine and validate that the execution was not tampered. Finally, POWERALERT randomizes the integrity checking program to prevent the attacker from adapting. We model the interaction between POWERALERT and an attacker as a time-continuous game. The Nash equilibrium strategy of the game shows that POWERALERT has two optimal strategy choices: (1) aggressive checking that forces the attacker into hiding, or (2) slow checking that minimizes cost. We implement a prototype of POWERALERT using Raspberry Pi and evaluate the performance of the integrity checking program generation.
机译:我们提出Poweralert,一个有效的外部完整性检查器,用于不受信任的主机。当前的证明系统遭受缺点,包括要求代码段的完整校验和,从静态,使用来自不受信任的机器的时序信息,或使用诸如网络往返时间的不精确定时信息。我们使用来自主机的功率测量来解决这些缺点(1),以确保执行检查代码和(2)在较长时段内检查内核空间的子集。我们将功率测量与机器执行的学习电源模型进行比较,并验证执行未被篡改。最后,Poweralert随机化了完整性检查程序以防止攻击者正在调整。我们将Poweralert和攻击者之间的互动模拟了一个时间连续游戏。游戏的纳什均衡策略表明,Poweralert有两个最佳的策略选择:(1)激进检查迫使攻击者隐藏,或(2)减慢检查最小化成本。我们使用覆盆子PI实施Poweralert的原型,并评估完整性检查程序生成的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号