CMD: Co-Analyzed IoT Malware Detection and Forensics via Network and Hardware Domains

计算机科学 恶意软件 网络取证 语义学(计算机科学) 寄主(生物学) 旁道攻击 人工智能 算法 计算机安全 密码学 程序设计语言 数字取证 生态学 生物
作者
Ziming Zhao,Zhaoxuan Li,Jiongchi Yu,Fan Zhang,Xiaofei Xie,Haitao Xu,Binbin Chen
出处
期刊:IEEE Transactions on Mobile Computing [IEEE Computer Society]
卷期号:23 (5): 5589-5603 被引量:17
标识
DOI:10.1109/tmc.2023.3311012
摘要

With the widespread use of Internet of Things (IoT) devices, malware detection has become a hot spot for both academic and industrial communities. Existing approaches can be roughly categorized into network-side and host-side. However, existing network-side methods are difficult to capture contextual semantics from cross-source traffic, and previous host-side methods could be adversary-perceived and expose risks for tampering. More importantly, a single perspective cannot comprehensively track the multi-stage lifecycle of IoT malware. In this paper, we present ${\sf CMD}$ , a co-analyzed IoT malware detection and forensics system by combining hardware and network domains. For the network part, ${\sf CMD}$ proposes a tailored capsule neural network to capture the contextual semantics from cross-source traffic. For the hardware part, ${\sf CMD}$ designs an entire file operation recovery process in a side-channel manner by leveraging the Serial Peripheral Interface (SPI) signals from on-chip traces. These traffic provenance and operating logs information could benefit the anti-virus countermeasures for security practitioners. By practical evaluation, we demonstrate that ${\sf CMD}$ realizes outstanding detection effects ( e.g., $\sim$ 99.88% F1-score) compared with seven state-of-the-art methods, and recovers 96.88% $\sim$ 99.75% operation commands even if against adaptive adversaries (that could kill processes or tamper with operation log files). A by-product benefit of such an external monitor is ${\sf CMD}$ introduces zero latency on the IoT device, and incurs negligible IoT CPU utilization. Also, since SPI focuses on file operations, the proposed hardware trace forensics does not have the data explosion problem like previous work, e.g., recovered logs of ${\sf CMD}$ only take up limited extra space overhead ( e.g., $\sim$ 0.2 MB per malware). Furthermore, we provide the model interpretability for the capsule network and develop a case study (Hajime) of the operation logs recovery.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
两滴水的云完成签到,获得积分10
刚刚
200126发布了新的文献求助10
刚刚
Fiona0518完成签到,获得积分10
刚刚
pcy发布了新的文献求助10
刚刚
hsj发布了新的文献求助10
刚刚
Sledge发布了新的文献求助10
1秒前
科研通AI6.4应助democienceek采纳,获得10
1秒前
隐形曼青应助阔达晓博采纳,获得10
1秒前
Zzhuuuuu完成签到,获得积分10
1秒前
丁丁完成签到,获得积分10
1秒前
2秒前
lufafa完成签到,获得积分10
2秒前
2秒前
CodeCraft应助shadow采纳,获得200
2秒前
夜已深发布了新的文献求助10
3秒前
小林发布了新的文献求助10
3秒前
3秒前
3秒前
瑞子完成签到,获得积分20
4秒前
丁丁发布了新的文献求助10
5秒前
123完成签到 ,获得积分10
5秒前
6秒前
micomico发布了新的文献求助10
6秒前
八个脑袋发布了新的文献求助10
6秒前
871004188发布了新的文献求助10
7秒前
赘婿应助cyf采纳,获得10
7秒前
7秒前
7秒前
v0id应助瑞子采纳,获得10
7秒前
人人人完成签到,获得积分10
7秒前
852应助Eujay采纳,获得10
7秒前
天天快乐应助71采纳,获得10
8秒前
SCI完成签到,获得积分10
8秒前
BZPL发布了新的文献求助10
8秒前
海a发布了新的文献求助30
8秒前
9秒前
随缘来一个吧完成签到 ,获得积分10
9秒前
英姑应助十一十八采纳,获得10
9秒前
10秒前
10秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Navigating Normative Orders. Interdisciplinary Perspectives 800
Organizational Behavior 510
Management and the Arts 510
Matrix Methods in Data Mining and Pattern Recognition Second Edition 510
CLSI VET01S-2024 Performance Standards for Antimicrobial Disk and Dilution Susceptibility Tests for Bacteria Isolated From Animals (7th Ed) 500
A Case Study on Hotels as Noncongregate Emergency Living Accommodations for Returning Citizens 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7757054
求助须知:如何正确求助?哪些是违规求助? 9303518
关于积分的说明 20274828
捐赠科研通 7340592
什么是DOI,文献DOI怎么找? 3311725
关于科研通互助平台的介绍 2462591
邀请新用户注册赠送积分活动 2325427