Independent Verification of Untrusted Systems: A Side-Channel Approach to Anomaly and Intrusion Detection

Loading...
Thumbnail Image

Journal Title

Journal ISSN

Volume Title

Publisher

University of Waterloo

Abstract

Compromised machines are not trustworthy. This simple and apparently obvious statement clashes with the way most Intrusion Detection Systems (IDSs) operate. Whether they analyze binaries, logs, files, or network traffic, they share the flaw of relying on software running on the monitored machine for information collection. But what if the machine is compromised? Should we still use and trust input data that may have been tampered with by an attacker? This flaw is the root of this investigation on side-channel-based IDS. To circumvent this lack of trust, it is required to move the information collection process out of the target and only consider independent and tamper-resistant information. Side-channel information is an ideal candidate for this task because its presence is guaranteed and its variations are intrinsically linked to the activity of the system. Moreover, measuring side-channel information does not require the cooperation of the system. Many side-channels are viable candidates but power consumption quickly proves to be the most practical, reliable, and available. Throughout successive studies, power consumption was leveraged to build complementary IDSs aiming to provide an additional layer of defence, one sitting at the very bottom of the technology stack. These studies revealed that the main obstacle for using power consumption to detect intrusion is the interpretation of the power patterns. The power consumption of a machine in the real world is noisy and inconsistent. In order to make a decision, each proposed algorithm first converts the real-valued time series into categorical and consistent information. This conversion of power patterns into actionable labels is the core of all approaches and thus relies on different techniques depending on the machine or the type of attack to detect. This thesis presents the results of developing and applying power capture, signal processing, machine learning, and intrusion detection tools to a wide range of devices to detect attacks such as firmware tampering, hardware tampering, unauthorized access, anomalous activities, and evasion techniques. Each study provides experiments performed with real-world machines to evaluate the capabilities of the proposed approaches to detect attacks. These studies led to the conclusion that power consumption is a viable source of information for the detection of a wide range of attacks and that its use as a complementary layer of defence would be beneficial for a wide range of devices.

Description

Citation

Collections

Endorsement

Review

Supplemented By

Referenced By