George Mason University
Securing Embedded Systems: from Device Level to Network Level
Abstract
As technology advances for IC design to IC manufacturing and integration into the IoT paradigm, security challenges are also increasing rapidly. In recent years, ICs have been su↵ering multi-dimensional security challenges from design to network/application stages. Rouge employees in an untrusted foundry may modify ICs and insert Hardware Trojans, locked ICs (in terms of logic-locked key gates) are su↵ering from SAT-based attacks. In addition, while deployed as IoT devices, these ICs face severe security challenges against malware attacks. In this dissertation, we propose a bottom-up solution to protect ICs from the design phase to the network phase. In the design phase, Hardware Trojans (HTs) poses a critical security threat to modern integrated circuits (ICs) through malicious activities, including leaking critical information, executing unauthorized commands, and reducing IC lifetime. Traditional functional and structural verification approaches are inecient in detecting stealthy Trojans e↵ectively due to corner conditions and rare triggers. Meanwhile, Trojan insertion occurs at various abstractions of the IC design; thus, adopting a more robust detection at the design stage is imperative. In order to address this challenge, we present an IC design-aware Trojan detection approach, where we extract di↵erent structural features of the underlying IC along with the behavioral information. Structural features such as node types and their respective counts and connectivity are extracted with behavioral information such as operating frequency and bit flip patterns extracted for the Golden and Trojan-inserted chip. We evaluate our proposed technique on Trust-Hub AES benchmark circuits with eight Trojan variants. Our experimental results achieve a detection accuracy of 98%, which shows that the model is capable of learning the structural feature distribution of the Golden Chip and di↵erentiates it from Trojan-inserted ones. Modern ICs face other design-phase challenges, including Reverse Engineering (RE), Intellectual Property (IP) theft, and IC overproduction. Against the aforementioned se- curity challenges, logic obfuscation provides a pivotal defense against multiple hardware threats ICs until the Boolean satisfiability (SAT) attack and its variants have been pro- posed in the literature. A plethora of countermeasures has also been proposed to thwart the SAT attack. Irrespective of the implemented defense against SAT attacks, large power, performance and area overheads are seen to be indispensable. In contrast, we propose a cognitive solution, a neural network-based SAT-hard clause translator, SATConda, that incurs a minimal area and power overhead while preserving the original functionality with enhanced security. SATConda is incubated with an SAT-hard clause generator that trans- lates the existing conjunctive normal form (CNF) through minimal perturbations, such as inclusion of pair of inverters or bu↵ers or adding new lightweight SAT-hard block depend- ing on the provided CNF. For ecient SAT-hard clause generation, SATConda is equipped with a multi-layer neural network that first learns the dependencies of features (literals and clauses), followed by a long-short-term memory (LSTM) network to validate and backprop- agate the SAT hardness for better learning and translation. Our proposed SATConda is evaluated on ISCAS’85 and ISCAS’89 benchmarks and is seen to successfully defend against multiple state-of-the-art SAT attacks devised for hardware RE. In addition, we also evaluate our proposed SATConda’s empirical performance against MiniSAT, Lingeling and Glucose SAT solvers that form the base for numerous existing SAT attacks. Next, we focus on the security challenges that modern ICs su↵er while deployed as IoT devices. As millions of IoT devices are interconnected together for better communication and computation, compromising even a single device opens a gateway for the adversary to access the network leading to an epidemic. It is pivotal to detect any malicious activity on a device and mitigate the threat. Among multiple feasible security threats, malware (mali- cious applications) poses a serious risk to modern IoT networks. A wide range of malware can replicate itself and propagate through the network via the underlying connectivity in the IoT networks making the malware epidemic inevitable. There exist several techniques ranging from heuristics to game-theory-based techniques to model malware propagation and minimize the impact on the overall network. The state-of-the-art game-theory-based approaches solely focus either on the network performance or the malware confinement but do not optimize both simultaneously. This dissertation proposes a throughput-aware game theory-based end-to-end IoT network security framework to confine the malware epidemic while preserving the overall network performance. We propose a two-player game with one player being the attacker and the other being the defender. Each player has three di↵er- ent strategies, and each strategy leads to a certain gain for that player with an associated cost. A tailored min-max algorithm was introduced to solve the game. We have evaluated our strategy on a 500-node network for di↵erent classes of malware and compared it with existing state-of-the-art heuristic and game theory-based solutions.Finally, we propose a Trust Evaluation Framework with dynamic access revocation tech- nique to secure IoT devices in a distributed IoT network. The proposed methodology collects trust-related attributes, such as malicious activity at the parent node level, by collecting system-level Hardware Performance counter (HPC) data and network level Wire- shark data from the child node periodically. The suggested paradigm has three di↵erent operating blocks to ensure a dynamic revocation of the authorization given when the node was originally added to the network. The first step is to use a Multilayer Perceptron (MLP) Machine Learning (ML) model to identify any potentially malicious activity at the node level monitoring from the parent node. The Trust score is calculated across all nodes using the probabilistic likelihood value that the machine learning model predicts. The framework takes the required actions, such as removing write permission or revoking all previously given rights, by evaluating the Trust Score. This way, in the event of an attack, the framework robustly and dynamically identifies the attacker and the victim node and delivers the necessary steps. The evaluation results demonstrate that our algorithm successfully detects malicious activity at the node level with an average accuracy of about 98%. The model determines the malicious node’s trust after successfully identifying the anomaly. Additionally, it dynamically takes measures like revoking read-only access or eliminating write access with about 95% accuracy based on that trust score.
Author and committee
dc:creator, dc:contributor.*- Author
-
- Hassan, Rakibul
Identifiers
dc:identifier.*- Identifier
- hdl:1920/13682
- OAI identifier oai:identifier
- oai:MARS:1920/13682