ANOMALY DETECTION USING HARDWARE PERFORMANCE COUNTERS ON A LARGE SCALE IOT DEPLOYMENT Context : • Deployment of secure and reliable energy management devices Issues : • Large scale deployment • Resources constrained IoT devices • Dynamic devices (updates) Hypothesis & approach : • Identical IoT devices • Attacks on devices uses more resources • Use HPC to characterize the software execution • Anomaly detection based on comparative analysis only | 1
HARDWARE PERFORMANCE COUNTERS ANALYSIS: HPC raw values HPC "derivative" values HPC HPC value "derivative" value For one device : Time Time HPC HPC value "derivative" value For ten devices including an attacked device : Time Time | 2
ARCHITECTURE AND TESTING PLATFORM : Server Feature extraction Device Legitimate software Periodic + counter enabling sending Periodic Pre-computation v save of v counters Series of counters Anomaly/outlier detection | 3
Recommend
More recommend