首页> 外文期刊>Computers & Security >Detecting firmware modification on solid state drives via current draw analysis
【24h】

Detecting firmware modification on solid state drives via current draw analysis

机译:通过电流绘制分析检测固态驱动器上的固件修改

获取原文
获取原文并翻译 | 示例

摘要

Solid State Drives (SSDs) have gained significant market share among data storage options in recent years due to increased speed and durability. But when compared to Hard Disk Drives (HDDs), SSDs contain additional complexity which must be managed in firmware. Some manufacturers make firmware updates available, but their proprietary protections leave end users unable to verify the authenticity of the firmware post installation. This means that attackers who are able to get a malicious firmware version installed on a victim SSD are able to operate with impunity, as the owner will have no tools for detection. We use a method for performing side channel analysis of the current drawn by an SSD to compare its behavior while running genuine firmware against its behavior when running modified firmware. We further test this method for robustness against changes in external factors such as temperature and supplied power. In each case, we train a binary classifier with samples of genuine as well as modified firmware activity and are able to discriminate between them with over 90% accuracy in most experiments. Solid State Drives are trusted to store and protect critical data, so verification of SSD firmware is an important step towards having trust and confidence in the growing landscape of embedded devices used for critical operations.
机译:由于速度和耐用性提高,近年来,固态驱动器(SSD)在数据存储选项中获得了显着的市场份额。但与硬盘驱动器(HDD)相比,SSD包含额外的复杂性,必须在固件中管理。有些制造商提供固件更新,但他们的专有保护留下最终用户无法验证固件后安装的真实性。这意味着能够在受害者SSD上安装恶意固件版本的攻击者能够以有罪不罚现象运行,因为所有者将没有检测工具。我们使用一种用于执行SSD汲取的电流的侧通道分析的方法,以比较其在运行修改修改固件时运行正品固件的行为。我们进一步测试了这种方法,以防止外部因素的变化,例如温度和供应的电力。在每种情况下,我们将二进制分类器带有正版样本以及修改的固件活动,并且能够在大多数实验中以超过90%的准确度区分它们。可信稳定状态驱动器可信存储和保护关键数据,因此SSD固件的验证是对用于关键操作的嵌入式设备的越来越多的景观具有信任和信心的重要一步。

著录项

  • 来源
    《Computers & Security》 |2021年第3期|102149.1-102149.18|共18页
  • 作者单位

    Computer Engineering and Cyber Security Research Group United States Naval Academy Annapolis MD USA;

    Computer Engineering and Cyber Security Research Group United States Naval Academy Annapolis MD USA;

    Computer Engineering and Cyber Security Research Group United States Naval Academy Annapolis MD USA;

    Computer Engineering and Cyber Security Research Group United States Naval Academy Annapolis MD USA;

    Computer Engineering and Cyber Security Research Group United States Naval Academy Annapolis MD USA;

    Computer Engineering and Cyber Security Research Group United States Naval Academy Annapolis MD USA;

    Computer Engineering and Cyber Security Research Group United States Naval Academy Annapolis MD USA;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Solid state drives; Firmware; Side channel analysis; Cyber security; Machine learning;

    机译:固态驱动器;固件;侧通道分析;网络安全;机器学习;
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号