Hardware Mechanism for Detecting Malicious Communication in IoT Devices by using Time-Series Processor Information
Kyohei Fujiwara, Ryotaro Kobayashi, Masahiko Kato · 2024
Recently, with the increasing number of Internet of Things (IoT) devices and the various attacks have been launched on them, IoT device security has become increasingly important. While various countermeasures exist, IoT device attacks have diversified, making it difficult for traditional perimeter defenses, such as firewalls and instruction prevention system, to prevent these varied attacks. Therefore, the zero trust framework, which enhances endpoint security, is required. However, due to the limited hardware resources of IoT devices, it is challenging to implement software based security measures on them. Therefore, we propose a hardware-based mechanism to detect malicious communications and evaluate its effectiveness. Unlike malware detection, detection of malicious communications is necessary to differentiate their features from those of normal programs running in the OS, regardless of whether a communication is legitimate or malicious. As features, we use window features extracted from processer information, which is one of the pieces of information obtained directly from hardware, and summarized as a time series. By considering daemon and other processes, we define classes, set thresholds, and evaluated the proposed mechanism. These measures increase classifier accuracy, thereby demonstrating the effectiveness of the proposed mechanism.