• DocumentCode
    3712889
  • Title

    ARMing the Trusted Platform Module pro-active system integrity monitoring focussing on peer system notification

  • Author

    Markus Maybaum;Jens Toelle

  • Author_Institution
    NATO Cooperative Cyber Defence Centre of Excellence, Filtri tee 12, EE-10132 Tallinn, Estonia
  • fYear
    2015
  • Firstpage
    1584
  • Lastpage
    1589
  • Abstract
    The concept of Trusted Computing offers a hardware platform based on which the integrity of IT systems is verified using a structured file-based signature hierarchy of all executable system components - from BIOS boot up to the execution of any user application. Current implementations detect integrity breaches at firmware and at file level so that suitable counter measures on a Trusted Computing system may be taken in almost real-time. This information - so far - either remains stored locally or in best case is forwarded at application layer leaving enough time for a smart malware to infect a peering system or to compromise application level communication. This paper introduces a new pro-active concept of integrity monitoring and reporting using the Trusted Platform Module to supervise the integrity of a system focusing on incident reporting to peering systems at link layer. For this concept we suggest the enhancement of the Trusted Platform Module by a new Attack Recognition Module to monitor a system in real time and to reliably notify peering systems about any integrity breach detected.
  • Keywords
    "Monitoring","Protocols","Malware","Peer-to-peer computing","Public key"
  • Publisher
    ieee
  • Conference_Titel
    Military Communications Conference, MILCOM 2015 - 2015 IEEE
  • Type

    conf

  • DOI
    10.1109/MILCOM.2015.7357671
  • Filename
    7357671