DocumentCode :
3712889
Title :
ARMing the Trusted Platform Module pro-active system integrity monitoring focussing on peer system notification
Author :
Markus Maybaum;Jens Toelle
Author_Institution :
NATO Cooperative Cyber Defence Centre of Excellence, Filtri tee 12, EE-10132 Tallinn, Estonia
fYear :
2015
Firstpage :
1584
Lastpage :
1589
Abstract :
The concept of Trusted Computing offers a hardware platform based on which the integrity of IT systems is verified using a structured file-based signature hierarchy of all executable system components - from BIOS boot up to the execution of any user application. Current implementations detect integrity breaches at firmware and at file level so that suitable counter measures on a Trusted Computing system may be taken in almost real-time. This information - so far - either remains stored locally or in best case is forwarded at application layer leaving enough time for a smart malware to infect a peering system or to compromise application level communication. This paper introduces a new pro-active concept of integrity monitoring and reporting using the Trusted Platform Module to supervise the integrity of a system focusing on incident reporting to peering systems at link layer. For this concept we suggest the enhancement of the Trusted Platform Module by a new Attack Recognition Module to monitor a system in real time and to reliably notify peering systems about any integrity breach detected.
Keywords :
"Monitoring","Protocols","Malware","Peer-to-peer computing","Public key"
Publisher :
ieee
Conference_Titel :
Military Communications Conference, MILCOM 2015 - 2015 IEEE
Type :
conf
DOI :
10.1109/MILCOM.2015.7357671
Filename :
7357671
Link To Document :
بازگشت