Iron-Dome: Securing IoT Networked Systems at Runtime by Network and Device Characteristics to Confine Malware Epidemics
Sanket Shukla, Abhijitt Dhavlle, Sai Manoj Pudukotai Dinakarrao, Houman Homayoun, Setareh Rafatirad · 2022 IEEE 40th International Conference on Computer Design (ICCD) · 2022
The rapid growth of IoT networks presents an enlarged "attack space" for the adversary and poses significant security risks on a large scale. A single device in a network that is compromised under the influence of a malware attack, has the potential to spread malware across the network. This leads to a plethora of attacks, including DoS and ceasing the network functionality. Given the scale of IoT networks and the connectivity among the devices, mere detection and quarantining of malware in IoT networks does not limit the propagation of malware in IoT networks. This work proposes an integrated defense, termed as "IRON-DOME", comprising of (1) an on-device application analyzer: Image-based Malware detector that utilizes grayscale images of executables, (2) Device dynamic behavior analysis: Reliable extraction and dynamic analysis of malware Hardware Performance Counter (HPC) values; and (3) Device communication trait analyzer: Uses network packet data analysis to confine and propagate malware in the IoT network. The proposed solution yields: (1) a runtime malware detection accuracy of 93% within 19 ns, (2) is resource and power efficient; it consumes 30% fewer resources and 40% less power than state-of-the art defense techniques.