首页> 外文期刊>IEEE transactions on dependable and secure computing >IDEA: Intrusion Detection through Electromagnetic-Signal Analysis for Critical Embedded and Cyber-Physical Systems
【24h】

IDEA: Intrusion Detection through Electromagnetic-Signal Analysis for Critical Embedded and Cyber-Physical Systems

机译:想法:通过临界嵌入式和网络物理系统的电磁信号分析来入侵检测

获取原文
获取原文并翻译 | 示例

摘要

We propose a novel framework called IDEA that exploits electromagnetic (EM) side-channel signals to detect malicious activity on embedded and cyber-physical systems (CPS). IDEA first records EM emanations from an uncompromised reference device to establish a baseline of reference EM patterns. IDEA then monitors the target device's EM emanations. When the observed EM emanations deviate from the reference patterns, IDEA reports this as an anomalous or malicious activity. IDEA does not require any resource or infrastructure on, or any modification to, the monitored system itself. In fact, IDEA is isolated from the target device, and monitors the device without any physical contact. We evaluate IDEA by monitoring the target device while it is executing embedded applications with malicious code injections such as Distributed Denial of Service (DDoS), Ransomware and code modification. We further implement a control-flow hijack attack, an advanced persistent threat, and a firmware modification on three CPSs: an embedded medical device called SyringePump, an industrial Proportional-Integral-Derivative (PID) Controller, and a Robotic Arm, using a popular embedded system, Arduino UNO. The results demonstrate that IDEA can detect different attacks with excellent accuracy (AUC > 99.5%, and 100 percent detection with less than 1 percent false positives) from distances up to 3 m.
机译:我们提出了一种名为IDEA的新颖框架,该想法利用电磁(EM)侧通道信号来检测嵌入式和网络物理系统(CPS)的恶意活动。想法首先将EM发射从一个不妥协的参考装置记录,以建立参考EM模式的基线。然后想法监控目标设备的EM发射物。当观察到的EM发射物偏离参考模式时,想法将其报告为一种异常或恶意活动。想法不需要任何资源或基础架构,或者对被监控的系统本身进行任何修改。事实上,想法是从目标设备隔离的,并在没有任何物理接触的情况下监控设备。我们通过监视目标设备来评估想法,同时执行具有恶意代码注入的嵌入式应用程序,例如分布式拒绝服务(DDOS),勒索软件和代码修改。我们进一步实施了控制流程劫持攻击,先进的持久性威胁,以及三个CPS的固件修改:嵌入式医疗设备称为Syringepump,工业比例 - 积分 - 衍生物(PID)控制器,以及使用流行的机器人手臂嵌入式系统,Arduino Uno。结果表明,思想可以从高达3米的距离检测具有优异精度(AUC> 99.5%,100%检测)的不同攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号