Bomberman: Defining and Defeating Hardware Ticking Timebombs at Design-time
Timothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew Hicks
摘要
To cope with ever-increasing design complexities, integrated circuit designers increase both the size of their design teams and their reliance on third-party intellectual property (IP). Both come at the expense of trust: it is computationally infeasible to exhaustively verify that a design is free of all possible malicious modifications (i.e., hardware Trojans). Making matters worse, unlike software, hardware modifications are permanent: there is no "patching" mechanism for hardware; and powerful: they serve as a foothold for subverting software that sits above. To counter this threat, prior work uses both static and dynamic analysis techniques to verify hardware designs are Trojan-free. Unfortunately, researchers continue to reveal weaknesses in these "one-size-fits-all", heuristic-based approaches. Instead of attempting to detect all possible hardware Trojans, we take the first step in addressing the hardware Trojan threat in a divide-and-conquer fashion: defining and eliminating Ticking Timebomb Trojans (TTTs), forcing attackers to implement larger Trojan designs detectable via existing verification and sidechannel defenses. Like many system-level software defenses (e.g., Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP)), our goal is to systematically constrict the hardware attacker's design space. First, we construct a definition of TTTs derived from their functional behavior. Next, we translate this definition into fundamental components required to realize TTT behavior in hardware. Using these components, we expand the set of all known TTTs to a total of six variants-including unseen variants. Leveraging our definition, we design and implement a TTTspecific dynamic verification toolchain extension, called Bomberman. Using four real-world hardware designs, we demonstrate Bomberman's ability to detect all TTT variants, where previous defenses fail, with <1.2% false positives.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- ATTRITION: Attacking Static Hardware Trojan Detection Techniques Using Reinforcement LearningVasudev Gohil, Hao Guo, Satwik Patnaik, Jeyavijayan RajendranCCS 2022 · 被引用 34 次
- AttackGNN: Red-Teaming GNNs in Hardware Security Using Reinforcement LearningVasudev Gohil, Satwik Patnaik, Dileep Kalathil, Jeyavijayan RajendranUSENIX Security 2024 · 被引用 9 次
- Jinn: Hijacking Safe Programs with TrojansKomail Dharsee, John CriswellUSENIX Security 2023
- PCSPOOF: Compromising the Safety of Time-Triggered EthernetAndrew D. Loveless, Linh Thi Xuan Phan, Ronald G. Dreslinski, Baris KasikciS&P 2023
它引用的顶会 Paper5
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- A2: Analog Malicious HardwareKaiyuan Yang, Matthew Hicks, Qing Dong, Todd M. Austin 等S&P 2016 · 被引用 242 次
- ICAS: an Extensible Framework for Estimating the Susceptibility of IC Layouts to Additive TrojansTimothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew HicksS&P 2020 · 被引用 35 次
相关 Paper
- Rethinking IC Layout Vulnerability: Simulation-Based Hardware Trojan Threat Assessment with High FidelityXinming Wei, Jiaxi Zhang, Guojie LuoS&P 2024 · 被引用 7 次
- Red Team vs. Blue Team: A Real-World Hardware Trojan Detection Case Study Across Four Modern CMOS Technology GenerationsEndres Puschner, Thorben Moos, Steffen Becker, Christian Kison 等S&P 2023
- Private Circuits III: Hardware Trojan-Resilience via Testing AmplificationStefan Dziembowski, Sebastian Faust, François-Xavier StandaertCCS 2016 · 被引用 27 次
- VIPR-PCB: a machine learning based golden-free PCB assurance frameworkAritra Bhattacharyay, Prabuddha Chakraborty, Jonathan Cruz, Swarup BhuniaDAC 2022 · 被引用 2 次
- GDSII-Guard: ECO Anti-Trojan Optimization with Exploratory Timing-Security Trade-OffsXinming Wei, Jiaxi Zhang, Guojie LuoDAC 2023 · 被引用 9 次
