首页> 外文会议>SPIE Defense + Commercial Sensing Conference >Instruction Level Program Tracking Using Electromagnetic Emanations
【24h】

Instruction Level Program Tracking Using Electromagnetic Emanations

机译:使用电磁散发指令级别程序跟踪

获取原文

摘要

Monitoring computer system activities on the instruction level provides more resilience to malware attacksbecause these attacks can be analyzed better by observing the changes on the instruction level. Assuming thesource code is available, many training signals can be collected to track the instruction sequence to detect whethera malware is injected or the system works properly. However, training signals have to be collected with highsampling rate to ensure that the signi cant features of these signals do not vanish. Since the clock frequenciesof the current computer systems are extremely high, we need to have a commercial device with high samplingrate, i.e. 10GHz, which either costs remarkably high, or does not exist. To eliminate the de ciencies regardingthe insu cient sampling rate, we propose a method to increase the sampling rate with the moderate commercialdevices for training symbols. In that respect, we rst generate some random instruction sequences which existin the inspected source code. Then, these sequences are executed in a for-loop, and emanated electromagnetic(EM) signals from the processor are collected by a commercially available device with moderate sampling rate,i.e. sampling rate is much smaller than the clock frequency. Lastly, we apply a mapping of the gathered samplesby utilizing modulo of their timings with respect to execution time of overall instruction sequence. As the nalstep, we provide some experimental results to illustrate that we successfully track the instruction sequence byapplying the proposed approach.
机译:监控指令级别的计算机系统活动为恶意软件攻击提供了更多的弹性因为通过观察指令级别的变化,可以更好地分析这些攻击。假设这一点源代码可用,可以收集许多训练信号以跟踪指令序列以检测是否注入恶意软件或系统正常工作。但是,必须用高训练信号收集采样率确保这些信号的Signi Cant功能不会消失。由于时钟频率当前的计算机系统非常高,我们需要拥有一个具有高采样的商业设备速率,即10GHz,其成本明显高,或者不存在。消除关于的de CeniesINSU CIET采样率,我们提出了一种用温和的商业增加采样率的方法用于训练符号的设备。在这方面,我们将生成一些存在的随机指令序列在检查的源代码中。然后,这些序列以用于环路和散发的电磁器执行(EM)来自处理器的信号由商业上可用的设备收集,具有中等采样率,即采样率远小于时钟频率。最后,我们应用收集样本的映射利用关于总指令序列的执行时间的时间的模拟。作为nal.步骤,我们提供了一些实验结果,以说明我们成功跟踪了指令序列申请建议的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号