Practical and Secure Software-Based Attestation
Markus Jakobsson, Karl-Anders Johansson · 2011
Software-based attestation can be used for guaranteed detection of any active malware on a device. This promises a significant advance in the battle against malware, including mobile malware. However, most software based attestation methods are either heuristic or unsuitable for mobile computing - and often both. One recent software-based attestation method uses so-called memory-printing to produce a software-based attestation technique with provable properties. We describe a novel memory-printing algorithm that improves on that work by being more than an order of magnitude faster, while avoiding commonly used and questionable security assumptions. This results in a truly practical and arguable secure solution - taking less than 3 seconds on a 600 MHz processor with 256 MB RAM. Our work finds applications to malware defense and trusted computing in general, and mobile malware defense in particular.