μThingNet: Leveraging Fine-Grained Power Analysis towards A Robust Zero-Day Defender

Zhuoran Li, Dan Zhao · 2023

Zero-day exploits on Internet of Things (IoT) devices, resurrected with new malware variants have caused a massive spike in botnet activities in early 2023. To address the aforementioned challenges, we propose a robust and universal fine-grained CPU security engine aimed at defending various IoT devices from the resurgence of cybercriminal activity and tactics, specifically targeting unknown variants. In contrast to previous methods that primarily rely on side-channel data leakage for detecting existing malware, our approach introduces a novel concept of leveraging a fine-grained power analysis model to extract the correlation between malware functionality and distinguishable power features to effectively train a compact deep learning architecture dubbed μThingNet. Specifically, a fine-grained analysis scheme is proposed to exploit a novel idea of "multiscale feature extraction" to identify the distinct behaviors of Mirai-based variants in a hierarchy of commands, functions, and modules on over 30,000 Mirai-based malware binary files collected from various CPU architectures via IoT Honeypot. The compact μThingNet architecture is designed with depthwise adaptive convolution and h-swish activation in lieu of the classic expansion layer and ReLU activation function to achieve superior performance to the current state of the art. Extensive experiments are conducted on IoT devices, which collect side-channel CPU power data via integrated current sensors. Based on the fine-grained power data analysis of Mirai variants, the μThingNet model demonstrates a detection rate of 97.49% on unknown variants at a detection speed of 2.148ms ~ 2.983ms.

Read the paper · More papers on PaperTik