Trustguard: a Containment Architecture with Verified Output

نویسنده

  • SOUMYADEEP GHOSH
چکیده

Computers today are so complex and opaque that a user cannot know everything occurring within the system. Most efforts toward computer security have focused on securing software. However, software security techniques implicitly assume correct execution by the underlying system, including the hardware. Securing these systems has been challenging due to their complexity and the proportionate attack surface they present during their design, manufacturing, deployment, and operation. Ultimately, the user’s trust in the system depends on claims made by each party supplying the system’s components. This dissertation presents the Containment Architecture with Verified Output (CAVO) model in recognition of the reality that existing tools and techniques are insufficient to secure complex hardware components in modern computing systems. Rather than attempt to secure each complex hardware component individually, CAVO establishes trust in hardware using a single, simple, separately manufactured component, called the Sentry. The Sentry bridges a physical gap between the untrusted system and its external interfaces and contains the effects of malicious behavior by untrusted system components before the external manifestation of any such effects. Thus, only the Sentry and the physical gap must be secured in order to assure users of the containment of malicious behavior. The simplicity and pluggability of CAVO’s Sentry enable suppliers and consumers to take additional measures to secure it, including formal verification, supervised manufacture, and supply chain diversification. This dissertation also presents TrustGuard—the first prototype CAVO design—to demonstrate the feasibility of the CAVO model. TrustGuard achieves containment by only allowing the communication of correctly executed results of signed software. The Sentry in TrustGuard leverages execution information obtained from the untrusted processor to enable efficient checking of the untrusted system’s work, even when the Sentry itself is simpler and much slower than the untrusted processor. Simulations show that TrustGuard can guarantee containment of malicious hardware components with a geomean of 8.5% decline

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Vigilante: End-to-End Containment of Internet Worms

Worm containment must be automatic because worms can spread too fast for humans to respond. Recent work has proposed network-level techniques to automate worm containment; these techniques have limitations because there is no information about the vulnerabilities exploited by worms at the network level. The authors propose Vigilante, a new end-to-end approach to contain worms automatically that...

متن کامل

A Hysteretic Two-phase Supply Modulator for Envelope Tracking RF Power Amplifiers

In this paper a two-phase supply modulator suitable for envelope tracking power amplifier is presented. The designed supply modulator has the linear assisted switching architecture. Two-phase architecture is used in order to reduce the output switching ripples. The proposed architecture uses hysteretic control instead of pulse width modulation (PWM) which significantly reduces the circuit compl...

متن کامل

Observer-based Adaptive Optimal Output Containment Control problem of Linear Heterogeneous Multi-agent Systems with Relative Output Measurements

1Department of Electrical Engineering, Ferdowsi University of Mashhad, Mashhad, Iran 2Department of Electrical Engineering, University of Semnan, Semnan, Iran 3Missouri University of Science and Technology, Rolla, MO 65401, USA Summary This paper develops an optimal relative output-feedback based solution to the containment control problem of linear heterogeneous multi-agent systems. A distribu...

متن کامل

Output containment control for swarm systems with general linear dynamics: A dynamic output feedback approach

Output containment control problems for high-order linear time-invariant swarm systems under directed interaction topologies are investigated using a dynamic output feedback approach. Firstly, to propel the outputs of followers to converge to the convex hull formed by the outputs of leaders, a dynamic output containment protocol is presented. Thennecessary and sufficient conditions for swarm sy...

متن کامل

Control of multivehicle systems in the presence of uncertain dynamics

In this paper, we present a cooperative control architecture for high-order multivehicle systems having non-identical nonlinear uncertain dynamics. The proposed methodology consists of a local cooperative controller and a vehicle-level controller for each vehicle. The former controller receives the relative output measurements of the neighboring vehicles in order to solve a containment problem ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2016