A sense of others: behavioral attestation of UNIX processes on remote platforms

  • Authors:
  • Toqeer Ali Syed;Roslan Ismail;Shahrulniza Musa;Mohammad Nauman;Sohail Khan

  • Affiliations:
  • Universiti Kuala Lumpur (UniKL), Malaysia;Universiti Kuala Lumpur (UniKL), Malaysia;Universiti Kuala Lumpur (UniKL), Malaysia;Universiti Kuala Lumpur (UniKL), Malaysia;Universiti Kuala Lumpur (UniKL), Malaysia

  • Venue:
  • Proceedings of the 6th International Conference on Ubiquitous Information Management and Communication
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

Remote attestation is a technique in Trusted Computing to verify the trustworthiness of a client platform. The most well-known method of verifying the client system to the remote end is the Integrity Measurement Architecture (IMA). IMA relies on the hashes of applications to prove the trusted state of the target system to the remote challenger. This hash-based approach leads to several problems including highly rigid target domains. To overcome these problems several dynamic attestation techniques have been proposed. These techniques rely on the runtime behavior of an application or data structures and sequence of system calls. In this paper we propose a new attestation technique that relies on the seminal work done in Sequence Time Delay Embedding (STIDE). We present our target architecture in which the client end is leveraged with STIDE and the short sequences of system call patterns associated with a process are measured and reported to the challenger. Furthermore, we investigate how this technique can shorten the reported data as compared to other system call-based attestation techniques. The primary advantage of this technique is to detect zero-day malware at the client platform. There are two most important metrics for the successful implementation of dynamic behavior attestation. One is the time required for processing on the target system and second is the network overhead. In our proposed model we concentrate on maximizing the efficiency of these metrics.