Practical and Secure Software-Based Attestation

  • Authors:
  • Markus Jakobsson;Karl-Anders Johansson

  • Affiliations:
  • -;-

  • Venue:
  • LIGHTSEC '11 Proceedings of the 2011 Workshop on Lightweight Security & Privacy: Devices, Protocols, and Applications
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

Software-based attestation can be used for guaranteed detection of any active malware on a device. This promises a significant advance in the battle against malware, including mobile malware. However, most software based attestation methods are either heuristic or unsuitable for mobile computing 聳 and often both. One recent software-based attestation method uses so-called memory-printing to produce a software-based attestation technique with provable properties. We describe a novel memory-printing algorithm that improves on that work by being more than an order of magnitude faster, while avoiding commonly used and questionable security assumptions. This results in a truly practical and arguable secure solution 聳 taking less than 3 seconds on a 600 MHz processor with 256 MB RAM. Our work finds applications to malware defense and trusted computing in general, and mobile malware defense in particular.