首页> 外文会议>SPIE Defense + Security Conference >CASPER: An efficient approach to detect anomalous code execution from unintended electronic device emissions
【24h】

CASPER: An efficient approach to detect anomalous code execution from unintended electronic device emissions

机译:Casper:一种有效的方法来检测来自意想到的电子设备排放的异常代码

获取原文

摘要

The CASPER system offers a lightweight, multi-disciplinary approach to detect the execution of anomalous code by monitoring the unintended electronic device emissions. Using commodity hardware and a combination of novel signal processing, machine learning, and program analysis techniques, we have demonstrated the ability to detect unknown code running on a device placed 12" from the CASPER system by analyzing the devices RF emissions. Our innovations for the sensors subsystem include multi-antenna processing algorithms which allow us to extend range and extract signal features in the presence of background noise and interference encountered in realistic training and monitoring environments. In addition, robust feature estimation methods have been developed that allow detection of device operating conditions in the presence of varying clock frequency and other aspects that may change from device to device or from training to monitoring. Furthermore, a band-scan technique has been implemented to automatically identify suitable frequency bands for monitoring based on a set of metrics including received power, expected spectral feature content (based on loop length and clock frequency), kurtosis, and mode clustering. CASPER also includes an auto-labeling feature that is used to discover the signal processing features that provide the greatest information for detection without human intervention. The system additionally includes a framework for anomaly detection engines, currently populated with three engines based on n-grams, statistical frequency, and control flow. As we will describe, the combination of these engines reduces the ways in which an attacker can adapt in an attempt to hide from CASPER. We will describe the CASPER concept, components and technologies used, a summary of results to-date, and plans for further development. CASPER is an ongoing research project funded under the DARPA LADS program.
机译:Casper系统提供了一种轻量级,多学科方法来通过监控意外的电子设备排放来检测异常代码的执行。使用商品硬件和新型信号处理,机器学习和程序分析技术的组合,我们已经证明了通过分析设备RF排放来检测从Casper系统放置12英寸的设备上运行的未知代码。我们的创新传感器子系统包括多天线处理算法,其允许我们在现实训练和监控环境中遇到的背景噪声和干扰存在中扩展范围和提取信号特征。此外,已经开发出允许检测设备的鲁棒特征估计方法在存在不同时钟频率和可能从设备到设备或训练的其他方面存在的条件。此外,已经实现了一种带扫描技术以基于包括接收的一组测量来自动识别用于监视的合适频带电源,预期谱特征内容(基于循环长度和时钟频率),Kurtosis和Mode Clustering。 Casper还包括一个自动标记功能,用于发现信号处理功能,提供最大的检测信息而不进行人为干预。该系统另外包括用于异常检测发动机的框架,目前基于N-GRAM,统计频率和控制流填充有三个发动机。正如我们将描述的那样,这些引擎的组合减少了攻击者可以适应尝试隐藏的方式的方式。我们将描述所使用的Casper概念,组件和技术,迄今为止的结果摘要,以及进一步发展的计划。 Casper是在DARPA LADS计划下资助的正在进行的研究项目。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号