ConFirm: Detecting Firmware Modifications in Embedded Systems using Hardware Performance Counters

International Conference on Computer-Aided Design(2015)

引用 114|浏览290
暂无评分
摘要
Critical infrastructure components nowadays use microprocessor-based embedded control systems. It is often infeasible, however, to employ the same level of security measures used in general purpose computing systems, due to the stringent performance and resource constraints of embedded control systems. Furthermore, as software sits atop and relies on the firmware for proper operation, software-level techniques cannot detect malicious behavior of the firmware. In this work, we propose ConFirm, a low-cost technique to detect malicious modifications in the firmware of embedded control systems by measuring the number of low-level hardware events that occur during the execution of the firmware. In order to count these events, ConFirm leverages the Hardware Performance Counters (HPCs), which readily exist in many embedded processors. We evaluate the detection capability and performance overhead of the proposed technique on various types of firmware running on ARM- and PowerPC-based embedded processors. Experimental results demonstrate that ConFirm can detect all the tested modifications with low performance overhead.
更多
查看译文
关键词
ConFirm,firmware modification detection,embedded systems,hardware performance counters,infrastructure components,microprocessor-based embedded control systems,security measures,computing systems,stringent performance,resource constraints,software-level techniques,malicious behavior detection,low-level hardware events,ARM-based embedded processors,PowerPC-based embedded processors
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要