Title :
StaticTrust: A Practical Framework for Trusted Networked Devices
Author :
Harris, Jack ; Hill, Raquel L.
Author_Institution :
Sch. of Inf. & Comput., Indiana Univ., Bloomington, IN, USA
Abstract :
Given the proliferation of malware and malicious activities, the integrity of communication systems is an ever growing concern. In this work, we propose StaticTrust, an integrity measurement framework which enables a system to evaluate the integrity and state of a remote client prior to providing trusted communication services. StaticTrust is designed for a specific class of network devices that have software images that change infrequently and require tight configuration control (e.g. routers, switches, trusted gateways, or high-low guards). StaticTrust exploits the relatively static nature of these communication systems and uses a Trusted Platform Module (TPM) to measure the state and provide identity verification for the device. This framework, coupled with the attestation and dynamic firewall exception services we authored, enables remote parties to confirm the integrity of clients, thereby limiting the effects and the proliferation of malware in a compromised system. We implement a prototype of the StaticTrust framework and measure the performance of our system to show that our design choices for constructing the software image result in efficient measurement and verification of system integrity.
Keywords :
authorisation; computer crime; computer network security; invasive software; StaticTrust; Trusted Platform Module; communication systems integrity; dynamic firewall exception services; malicious activities; malware; software images; system integrity; trusted communication services; trusted networked devices; Hardware; Peer to peer computing; Security; Size measurement; Software; Software measurement; Time measurement;
Conference_Titel :
System Sciences (HICSS), 2011 44th Hawaii International Conference on
Conference_Location :
Kauai, HI
Print_ISBN :
978-1-4244-9618-1
DOI :
10.1109/HICSS.2011.384