首页> 外文会议>IEEE International Symposium on Hardware Oriented Security and Trust >Remote attestation of IoT devices via SMARM: Shuffled measurements against roving malware
【24h】

Remote attestation of IoT devices via SMARM: Shuffled measurements against roving malware

机译:通过SMARM进行IoT设备的远程认证:针对漫游恶意软件的混洗测量

获取原文

摘要

Remote Attestation (RA) is a popular means of detecting malware presence on embedded and IoT devices. It is especially relevant to low-end devices that are incapable of protecting themselves against infection. Malware that is aware of ongoing or impending RA and aims to avoid detection can relocate itself during computation of the attestation measurement. In order to thwart such behavior, prior RA techniques are either non-interruptible or explicitly forbid modification of storage during measurement computation. However, since the latter can be a time-consuming task, this curtails availability of device's other (main) functions, which is especially undesirable, or even dangerous, for devices with time-and/or safety-critical missions. In this paper, we propose SMARM, a light-weight technique, based on shuffled measurements, as a defense against roving malware. In SMARM, memory is measured in a randomized and secret order. This does not impact device's availability - the measurement process can be interrupted, even by malware, which can relocate itself at will. We analyze various malware behaviors and show that, while malware can escape detection in a single attestation instance, it is highly unlikely to avoid eventual detection.
机译:远程证明(RA)是一种检测嵌入式和IoT设备上是否存在恶意软件的流行方法。这对于无法保护自己免受感染的低端设备尤其重要。知道正在进行的RA或即将发生的RA并旨在避免检测的恶意软件可以在证明度量的计算过程中自行重定位。为了阻止这种行为,现有的RA技术要么是不可中断的,要么是在测量计算期间明确禁止修改存储。但是,由于后者可能是一项耗时的任务,因此降低了设备其他(主要)功能的可用性,这对于执行具有时间和/或安全要求严格的任务的设备而言,是特别不希望的,甚至是危险的。在本文中,我们提出了一种基于混洗测量的轻量级技术SMARM,可以抵御巡回恶意软件。在SMARM中,内存是以随机和秘密的顺序进行测量的。这不会影响设备的可用性-测量过程可能会中断,即使是恶意软件也可能会中断,恶意软件会自行重新定位。我们分析了各种恶意软件行为,并表明,尽管恶意软件可以在单个证明实例中逃脱检测,但极不可能避免最终检测。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号