PowerAlert: An Integrity Checker using Power Measurement

نویسندگان

  • Ahmed M. Fawaz
  • Mohammad A. Noureddine
  • William H. Sanders
چکیده

We propose POWERALERT, an efficient external integrity checker for untrusted hosts. Current attestation systems suffer from shortcomings in requiring complete checksum of the code segment, being static, use of timing information sourced from the untrusted machine, or use of timing information with high error (network round trip time). We address those shortcomings by (1) using power measurements from the host to ensure that the checking code is executed and (2) checking a subset of the kernel space over a long period of time. We compare the power measurement against a learned power model of the execution of the machine and validate that the execution was not tampered. Finally, power diversifies the integrity checking program to prevent the attacker from adapting. We implement a prototype of POWERALERT using Raspberry pi and evaluate the performance of the integrity checking program generation. We model the interaction between POWERALERT and an attacker as a game. We study the effectiveness of the random initiation strategy in deterring the attacker. The study shows that POWERALERT forces the attacker to trade-off stealthiness for the risk of detection, while still maintaining an acceptable probability of detection given the long lifespan of stealthy attacks.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

The validation of one halitosis measuring device (Etiquette checker)‎

BACKGROUND AND AIM: Various measurement devices are available for detection of halitosis. For epidemiologic studies, it is necessary to use a portable and small device. This study aimed to investigation of correlation between measuring the device (Etiquette checker) with Halimeter. METHODS: One hundred volunteers (students and patients) participated in this study. The amount of volatile sulfur ...

متن کامل

Offline Integrity Checking of Untrusted Storage

We extend the offline memory correctness checking scheme presented by Blum et. al [BEG91] to develop an offline checker that can detect attacks by active adversaries. We introduce the concept of incremental multiset hashes, and detail one example: MSet-XOR MAC, which uses a secret key, and is efficient as updating the hash costs a few hash and XOR operations. Using multiset hashes as our underl...

متن کامل

Connectivity as a Measure of Power System Integrity

Measures of network structural integrity useful in the analysis and synthesis of power systems are discussed. Signal flow methodology is applied to derive an expression for the paths between sources and sinks in a power network. Connectivity and reach ability properties of the network are obtained using the minors of a modified connectivity matrix. Node-connectivity, branch connectivity and mix...

متن کامل

File Integrity Checkers: State of the Art and Best Practices

Assuring that system files have not been tampered with over time is a vital, but oftoverlooked, aspect of system security. File integrity checkers provide ways to assure the validity of files on a system. This paper concerns itself with a review of file integrity checkers. It pays particular attention to what the minimum requirements for an integrity checker are, the different approaches taken ...

متن کامل

Binary Integrity Constraints Against Confidentiality

Any protection mechanism opens an unexpected channel of communication, the so-called covert channel. The Integrity Checker of a database is a protection mechanism, against data inconsistencies. As such, it opens a covert channel which can be used to thwart the mechanism which ensures confidentiality. Therefore, confidential data can be unveiled leading to a « the more semantic, the less secure ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • CoRR

دوره abs/1702.02907  شماره 

صفحات  -

تاریخ انتشار 2017