On the Impacts of Shared-Resource Contention on Intrusion Detection Systems based on Performance Monitoring

Leonardo Passig Horstmann, Antônio Augusto Fröhlich, Marcus Völp · 2024

Modern embedded systems integrate software components onto a single computing platform to meet stringent non-functional requirements of cost, space, weight, and power consumption, amongst others. Moreover, the growing demand for computational power pushed for the adoption of multicore platforms. At the same time, those platforms are often connected to the external world to support a variety of applications. In this context, Machine Learning-based Intrusion Detection Systems (IDS) are of significant importance to guarantee the system’s security during its operation. One approach to be adopted by IDS is to model the behavior of the applications on an embedded system through Performance Monitoring Counters (PMC) and operate during runtime by detecting deviations to the modeled behavior. Notwithstanding, the execution of multiple tasks onto the same multicore platform often incurs shared-resource contention between tasks, which may impair the execution of software components and possibly affect the behavior observed through PMC. In this paper, we assess the impacts of lacking proper resource isolation mechanisms on multicore embedded systems over two Machine Learning-based Intrusion Detection Systems (IDS) solutions that rely on PMC. We use a relevant dataset in the scope of embedded systems control with both tasks monitored while executing without and with the interference of shared-resources contention. Results demonstrate that the lack of isolation can lead to the IDS mechanism losing the ability to recognize the behavior of target software components.

Read the paper · More papers on PaperTik