Systems, methods, and apparatuses for intrusion detection and analytics using power characteristics such as side-channel information collection
First Claim
1. An apparatus, comprising:
- a probe configured to capture side-channel information relating to an operation status of a target device, the probe in a permanently fixed position relative to the target device during a life span of anomaly detection on the target device;
a fixture, configured to fixedly hold the probe such that the probe is in a permanently fixed position relative to the target device;
a processor, communicatively coupled to the probe, configured to;
process the side-channel information to extract a first characteristic of the side-channel information,retrieve previously-stored reference side-channel information having a second characteristic and representing a normal activity of the target device,compare the first characteristic with the second characteristic to determine an anomaly of the target device, andsend to a user interface an alert indicative of the anomaly based on the first characteristic and the second characteristic.
1 Assignment
0 Petitions
Accused Products
Abstract
Some embodiments described herein include a system that collects and learns reference side-channel normal activity, process it to reveal key features, compares subsequent collected data and processed data for anomalous behavior, and reports such behavior to a management center where this information is displayed and predefine actions can be executed when anomalous behavior is observed. In some instances, a physical side channel (e.g. and indirect measure of program execution such as power consumption or electromagnetic emissions and other physical signals) can be used to assess the execution status in a processor or digital circuit using an external monitor and detect, with extreme accuracy, when an unauthorized execution has managed to disrupt the normal operation of a target system (e.g., a computer system, etc.).
-
Citations
20 Claims
-
1. An apparatus, comprising:
-
a probe configured to capture side-channel information relating to an operation status of a target device, the probe in a permanently fixed position relative to the target device during a life span of anomaly detection on the target device; a fixture, configured to fixedly hold the probe such that the probe is in a permanently fixed position relative to the target device; a processor, communicatively coupled to the probe, configured to; process the side-channel information to extract a first characteristic of the side-channel information, retrieve previously-stored reference side-channel information having a second characteristic and representing a normal activity of the target device, compare the first characteristic with the second characteristic to determine an anomaly of the target device, and send to a user interface an alert indicative of the anomaly based on the first characteristic and the second characteristic. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. An apparatus, comprising:
-
a circuit anomaly detector configured to monitor a change of state in a pin of a target circuit chip that indicates that a reprogrammable component on the target circuit chip is reprogrammed from initial manufacture to end of operation of the target circuit chip; and a notification processor communicatively coupled to the circuit anomaly detector, configured to transmit a notification message including a representation of the change of state, to an entity designated to respond to a detected anomaly. - View Dependent Claims (9, 10, 11, 12, 13, 14, 15, 16, 17, 18)
-
-
19. An apparatus comprising:
-
a circuit anomaly detector configured to monitor a change of state in a in of a target circuit chip that indicates that a reprogrammable component on the target circuit chip is reprogrammed, the target circuit chip including firmware, the change of state in the pin of the target circuit chip associated with a patch for the firmware, and a notification processor communicatively coupled to the circuit anomaly detector, configured to transmit a notification message to an entity designated to respond to a detected anomaly, the notification message indicating that the change of state is associated with the patch.
-
-
20. An apparatus comprising:
-
a circuit anomaly detector configured to monitor a first change of state in a pin of a target circuit chip at a first time that indicates that a reprogrammable component on the target circuit chip is reprogrammed; and the circuit anomaly detector is configured to monitor a second change of state in the pin of the target circuit chip at a second time after the first time, a notification processor communicatively coupled to the circuit anomaly detector, configured to transmit a notification message including a representation of the change of state, to an entity designated to respond to a detected anomaly, the notification message including a time-related performance parameter of the target circuit chip based on the first change of state and the second change of state.
-
Specification