DocumentCode
3712889
Title
ARMing the Trusted Platform Module pro-active system integrity monitoring focussing on peer system notification
Author
Markus Maybaum;Jens Toelle
Author_Institution
NATO Cooperative Cyber Defence Centre of Excellence, Filtri tee 12, EE-10132 Tallinn, Estonia
fYear
2015
Firstpage
1584
Lastpage
1589
Abstract
The concept of Trusted Computing offers a hardware platform based on which the integrity of IT systems is verified using a structured file-based signature hierarchy of all executable system components - from BIOS boot up to the execution of any user application. Current implementations detect integrity breaches at firmware and at file level so that suitable counter measures on a Trusted Computing system may be taken in almost real-time. This information - so far - either remains stored locally or in best case is forwarded at application layer leaving enough time for a smart malware to infect a peering system or to compromise application level communication. This paper introduces a new pro-active concept of integrity monitoring and reporting using the Trusted Platform Module to supervise the integrity of a system focusing on incident reporting to peering systems at link layer. For this concept we suggest the enhancement of the Trusted Platform Module by a new Attack Recognition Module to monitor a system in real time and to reliably notify peering systems about any integrity breach detected.
Keywords
"Monitoring","Protocols","Malware","Peer-to-peer computing","Public key"
Publisher
ieee
Conference_Titel
Military Communications Conference, MILCOM 2015 - 2015 IEEE
Type
conf
DOI
10.1109/MILCOM.2015.7357671
Filename
7357671
Link To Document