<p>The increasing prevalence of cyberattacks has made the security of Internet of Things (IoT) devices an urgent challenge. However, due to the limited resources and processing capabilities of IoT devices, such as their CPU and memory, deploying antivirus software is not a practical solution. To address this issue, machine learning-based malware detection mechanisms that utilize processor information during program execution have been extensively studied. Although these approaches leverage machine learning, they are typically implemented entirely in hardware. However, malware detection based on hash values has not been realized in hardware implementations. In this paper, we propose a novel detection circuit for identifying malware. This circuit is implemented entirely in hardware and operates in parallel with the cores of Large Scale Integrated (LSI) circuits. The proposed detection circuit achieves malware detection using a new type of hash value, referred to as Fixed-Interval Discrete Hash (FID-Hash), which differs from conventional hash values. In addition to verifying the number of hash value matches, we evaluate the circuit scale and power consumption of the proposed detection circuit to validate its feasibility for hardware implementation. The results revealed that malware hash values exhibited a high match rate with the definition table, whereas the hash values of the normal programs showed no matches.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A circuit for detecting IoT malware using signatures derived from processor information on LSI

  • Yutaro Matunaka,
  • Kazuma Tachihana,
  • Ryotaro Kobayashi,
  • Masahiko Kato

摘要

The increasing prevalence of cyberattacks has made the security of Internet of Things (IoT) devices an urgent challenge. However, due to the limited resources and processing capabilities of IoT devices, such as their CPU and memory, deploying antivirus software is not a practical solution. To address this issue, machine learning-based malware detection mechanisms that utilize processor information during program execution have been extensively studied. Although these approaches leverage machine learning, they are typically implemented entirely in hardware. However, malware detection based on hash values has not been realized in hardware implementations. In this paper, we propose a novel detection circuit for identifying malware. This circuit is implemented entirely in hardware and operates in parallel with the cores of Large Scale Integrated (LSI) circuits. The proposed detection circuit achieves malware detection using a new type of hash value, referred to as Fixed-Interval Discrete Hash (FID-Hash), which differs from conventional hash values. In addition to verifying the number of hash value matches, we evaluate the circuit scale and power consumption of the proposed detection circuit to validate its feasibility for hardware implementation. The results revealed that malware hash values exhibited a high match rate with the definition table, whereas the hash values of the normal programs showed no matches.