9 CORNER SOLUTIONS LLC — Department of Homeland Security SBIR Phase I: DHS231-001

9 CORNER SOLUTIONS LLC — SBIR Phase I award from Department of Homeland Security.

Amount
$149,972
Agency
Department of Homeland Security
Program / Phase
SBIR · Phase I
Topic
DHS231-001
Solicitation
23.1
NAICS
Place of performance
VA
Period
2023-05-09 → 2023-10-08

Description

The grand vision of the Internet-of-Things (IoT) boasts a fully connected, global network of devices or systems connecting every imaginable thing. Amelioration of miniature embedded computing devices into the consumer and industrial markets with enabled connectivity to the Internet towards smart and intelligent features leads to an upsurge in the size of networks through which they are linked and communicate. Unfortunately, with the massive amount of potential benefits offered by IoT devices comes an equal amount of potential vulnerabilities and cyber-threats including such as Malware, ransomware, and distributed denial-of-service (DDoS) attacks. Detection and defense of cyber-threats in IoT devices are traditionally performed by anti-virus (AV) software. However, AV-based threat detection has significant setbacks including large latency, processing overheads, inability to effectively detect zero-day attacks, and requirement of frequent updates. In this project, we propose the design of hardware-assisted runtime cyber-threat detection. We employ hardware-generated microarchitectural event traces captured through hardware performance counter (HPC) register information to extract the application characteristics to detect cyber-threats. To minimize overheads and facilitate runtime feasibility, an automated learning-based optimal feature extraction is designed. These features are fed to a lightweight machine learning (ML) classifier to detect the feasibility of the presence of cyber-threat. This is complemented with a specialized ML classifier in the second stage for enhanced performance. The second stage ML classifier also employs a time-series-based anomaly detection for zero-day and unseen threat detection. The portability of the proposed solution across different architectures and vendors enables commercialization seamlessly.