Towards Scalable EM-based Anomaly Detection For Embedded Devices Through Synthetic Fingerprinting

02/05/2023
by   Kurt A. Vedros, et al.
0

Embedded devices are omnipresent in modern networks including the ones operating inside critical environments. However, due to their constrained nature, novel mechanisms are required to provide external, and non-intrusive anomaly detection. Among such approaches, one that has gained traction is based on the analysis of the electromagnetic (EM) signals that get emanated during a device's operation. However, one of the most neglected challenges of this approach is the requirement for manually gathering and fingerprinting the signals that correspond to each execution path of the software/firmware. Indeed, even simple programs are comprised of hundreds if not thousands of branches thus, making the fingerprinting stage an extremely time-consuming process that involves the manual labor of a human specialist. To address this issue, we propose a framework for generating synthetic EM signals directly from the machine code. The synthetic signals can be used to train a Machine Learning based (ML) system for anomaly detection. The main advantage of the proposed approach is that it completely removes the need for an elaborate and error-prone fingerprinting stage, thus, dramatically increasing the scalability of the corresponding protection mechanisms. The experimental evaluations indicate that our method provides high detection accuracy (above 90 when employed for the detection of injection attacks. Moreover, the proposed methodology inflicts only a small penalty (-1.3 of the injection of as little as four malicious instructions when compared to the same methods if real signals were to be used.

READ FULL TEXT
research
12/12/2022

Detecting Code Injections in Noisy Environments Through EM Signal Analysis and SVD Denoising

The penetration of embedded devices in networks that support critical ap...
research
06/21/2022

A Practical Methodology for ML-Based EM Side Channel Disassemblers

Providing security guarantees for embedded devices with limited interfac...
research
08/12/2020

Rule-based Anomaly Detection for Railway Signalling Networks

We propose a rule-based anomaly detection system for railway signalling ...
research
10/27/2020

Anomaly detection in injection molding process data based on unsupervised learning

Plastic processing companies in high-wage countries are facing continuou...
research
10/04/2022

AnoML-IoT: An End to End Re-configurable Multi-protocol Anomaly Detection Pipeline for Internet of Things

The rapid development in ubiquitous computing has enabled the use of mic...
research
06/28/2022

Online Anomaly Detection Based On Reservoir Sampling and LOF for IoT devices

The growing number of IoT devices and their use to monitor the operation...
research
04/05/2022

PDNPulse: Sensing PCB Anomaly with the Intrinsic Power Delivery Network

The ubiquitous presence of printed circuit boards (PCBs) in modern elect...

Please sign up or login with your details

Forgot password? Click here to reset