Using Current Draw Analysis to Identify Suspicious Firmware Behavior in Solid State Drives
Ryan S. McDowell, Hau Ngo, Ryan N. Rakvic, T. Owens Walker, Robert W. Ives, Dane Brown · 2019
Solid State Drives (SSDs) are increasingly replacing traditional computer hard drives. However, SSDs are controlled by complex and potentially vulnerable firmware, and users cannot directly confirm if the firmware is behaving properly. This paper studies whether current draw analysis could identify suspicious firmware behavior. Specifically, we studied encryption, a frequent submodule of malware. We created four different firmware variants for an open-source SSD, two of which performed encryption, and then recorded their current draw as the firmware variants performed write operations with files of varying size. 1280 recordings were used to train three types of classifiers, which would attempt to distinguish between these firmwares. Using these recordings and the classification methods of previous researchers yielded just 51% and 58% accuracy when detecting simple (XOR) and industrial-level (AES) encryption, respectively. In contrast, we introduced a different classification pipeline that provided little gain with XOR but increased accuracy with the more realistic AES to better than 95%. These results demonstrate the potential of current draw analysis for detecting some malicious firmware and provide a basis for future development of more complex detection methods.