Mobile Malware: Why the traditional AV paradigm is doomed, and how - - PowerPoint PPT Presentation

mobile malware why the traditional av paradigm is doomed
SMART_READER_LITE
LIVE PREVIEW

Mobile Malware: Why the traditional AV paradigm is doomed, and how - - PowerPoint PPT Presentation

Mobile Malware: Why the traditional AV paradigm is doomed, and how to use physics to detect physics to detect undesirable routines Guy Stewart VP Engineering Fatskunk Inc. The Malware Problem The Malware Problem Trojans, Rootkits, the


slide-1
SLIDE 1

Mobile Malware: Why the traditional AV paradigm is doomed, and how to use physics to detect physics to detect undesirable routines

Guy Stewart VP Engineering Fatskunk Inc.

slide-2
SLIDE 2

The Malware Problem

Trojans, Rootkits, the Zero Day Apocalypse

The Malware Problem

slide-3
SLIDE 3

Threats

slide-4
SLIDE 4

Threats

slide-5
SLIDE 5

Untrustworthy Supply Chains

slide-6
SLIDE 6

Software Attestation

Introduction to Software Attestation using Principles of Physics

Software Attestation

slide-7
SLIDE 7

Approach: Measure by Displacement

slide-8
SLIDE 8

The software Space / Time trade-off

slide-9
SLIDE 9

Approach

  • 1. Stop execution of all programs

(malware may refuse) monolith kernel malware cache malware honest software, data,

  • r passive malware
slide-10
SLIDE 10

Approach

  • 1. Stop execution of all programs

(malware may refuse)

  • 2. Overwrite “free” memory with

pseudo-random content (malware refuses again) monolith kernel malware cache malware

slide-11
SLIDE 11

Approach

  • 1. Stop execution of all programs

(malware may refuse)

  • 2. Overwrite “free” memory with pseudo-

random content (malware refuses again) malware monolith kernel cache again)

  • 3. Compute keyed digest of all

memory (access order unknown a priori) malware

slide-12
SLIDE 12

Verify results

slide-13
SLIDE 13

Commercial Applications

slide-14
SLIDE 14

Secure Execution Environment (SXE)

slide-15
SLIDE 15

OS Secure Boot

slide-16
SLIDE 16

TrustZone Normal World

slide-17
SLIDE 17

Interconnected Embedded Systems

Verifier Client Verifier Client Client

slide-18
SLIDE 18

FatSkunk.com Guy Stewart : Guy@FatSkunk.com