TY - JOUR
T1 - Detecting air-gapped attacks using machine learning
AU - Zhu, Weijun
AU - Rodrigues, Joel J.P.C.
AU - Niu, Jianwei
AU - Zhou, Qinglei
AU - Li, Yafei
AU - Xu, Mingliang
AU - Huang, Bohu
N1 - Publisher Copyright:
© 2018 Elsevier B.V.
PY - 2019/10
Y1 - 2019/10
N2 - A GSMem malware can attack a computer connected physically with no network. However, none of the existing techniques can detect GSMem attacks, up to now. To address this problem, this paper puts forward a new method based on Machine Learning (ML), including Logistic Regression (LR), Random Forest (RF), Support Vector Machine (SVM), Boosted Tree (BT), Back-Propagation Neural Networks (BPNN) and Naive Bayes Classifier (NBC). At first, we use a large quantity of data in terms of frequencies and amplitudes of some electromagnetic waves to train our models. And then, we use the obtained models to predict that whether a GSMem attack occurs or not, according to a given frequency and amplitude. In a word, the GSMem intrusion detection problem is induced to a ML binary classification one, while the former problem is pending and the latter one has been solved. As a result, the former problem can be solved in principle in this way. The simulated experiments show that the new method is potential to detect a GSMem attack, with low False Positive Rates (FPR) and low False Negative Rates (FNR).
AB - A GSMem malware can attack a computer connected physically with no network. However, none of the existing techniques can detect GSMem attacks, up to now. To address this problem, this paper puts forward a new method based on Machine Learning (ML), including Logistic Regression (LR), Random Forest (RF), Support Vector Machine (SVM), Boosted Tree (BT), Back-Propagation Neural Networks (BPNN) and Naive Bayes Classifier (NBC). At first, we use a large quantity of data in terms of frequencies and amplitudes of some electromagnetic waves to train our models. And then, we use the obtained models to predict that whether a GSMem attack occurs or not, according to a given frequency and amplitude. In a word, the GSMem intrusion detection problem is induced to a ML binary classification one, while the former problem is pending and the latter one has been solved. As a result, the former problem can be solved in principle in this way. The simulated experiments show that the new method is potential to detect a GSMem attack, with low False Positive Rates (FPR) and low False Negative Rates (FNR).
KW - Air-gapped computers
KW - GSMem
KW - Machine learning
UR - https://www.scopus.com/pages/publications/85056701518
U2 - 10.1016/j.cogsys.2018.10.018
DO - 10.1016/j.cogsys.2018.10.018
M3 - 文章
AN - SCOPUS:85056701518
SN - 2214-4366
VL - 57
SP - 92
EP - 100
JO - Cognitive Systems Research
JF - Cognitive Systems Research
ER -