Charalambos Konstantinou

dblp:145/9428 · DBLP profile ↗
← Back
28ranked-venue papers
4as first author
16since 2021 · last 2026
0000-0002-3825-3930ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 11 · 3 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 1 first-author · 6 since 2021Computer networks · 4 · 4 since 2021Security and privacy · 4 · 4 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 1 since 2021
YearPublicationVenuePosition
2026 A Reality Check on SBOM-based Vulnerability Management: An Empirical Study and A Path Forward
abstract
The Software Bill of Materials (SBOM) is a critical tool for securing the software supply chain (SSC), but its practical utility is undermined by inaccuracies in both its generation and its application in vulnerability scanning. This paper presents a large-scale empirical study on 2,414 open-source repositories to address these issues from a practical standpoint. First, we demonstrate that using lock files with strong package managers enables the generation of accurate and consistent SBOMs, establishing a reliable foundation for security analysis. Using this high-fidelity foundation, however, we expose a more fundamental flaw in practice: downstream vulnerability scanners produce a staggering 92.0% false positive rate in our case study. We pinpoint the primary cause as the flagging of vulnerabilities within unreachable code. We then demonstrate that function call analysis can effectively prune 61.9% of these false alarms. Our work validates a practical, two-stage approach for SSC security: first, generate an accurate SBOM using lock files and strong package managers, and second, enrich it with function call analysis to produce actionable, low-noise vulnerability reports that alleviate developers' alert fatigue.
Marc Dacier, Charalambos Konstantinou
CODASPY3
2026 Sunspec Modbus Based Smart Inverter Cyber-Attack Modeling and Mitigation Scheme
Mohd Asim Aftab, S. M. Suhail Hussain, Shaik Mullapathi Farooq, Murali Sankar Venkatraman, Shehab Ahmed, Charalambos Konstantinou
IEEE Trans. Ind. Informatics6
2025 Robust Power System State Estimation Using Physics-Informed Neural Networks
abstract
Modern power systems face significant challenges in state estimation and real-time monitoring, particularly regarding response speed and accuracy under faulty conditions or cyber-attacks. This article proposes a hybrid approach using physics-informed neural networks (PINNs) to enhance the accuracy and robustness of power system state estimation. By embedding physical laws into the neural network architecture, PINNs improve estimation accuracy for transmission grid applications under both normal and faulty conditions, while also showing potential in addressing security concerns, such as data manipulation attacks. Experimental results show that the proposed approach outperforms traditional machine learning models, achieving up to$\sim$83% higher accuracy on unseen subsets of the training dataset and$\sim$65% better performance on entirely new, unrelated datasets. Experiments also show that during a data manipulation attack against a critical bus in a system, the PINN can be up to$\sim$93% more accurate than an equivalent neural network.
Solon Falas, Markos Asprou, Charalambos Konstantinou, Maria K. Michael
IEEE Trans. Ind. Informatics3
2024 CMXsafe: A Proxy Layer for Securing Internet-of-Things Communications
abstract
Security in Internet-of-Things (IoT) environments has become a major concern. This is partly due to a large number of remotely exploitable IoT vulnerabilities in service authentication and access control combined with the lack of timely technical support. To reduce the threat surface of remote vulnerability exploitation, we propose CMXsafe, a secure-by-design application-agnostic proxy layer that can be updated and managed independently of the IoT device application. CMXsafe places IoT devices behind gateways operating as 4th OSI transport layer relayers to offload security concerns of IoT network communications into the proxy layer. More Specifically, the proxy layer produces secure communication paths between IoT applications and platforms while enforcing mutual authentication and access control to proxied services. We evaluate the performance of our architecture on the MQTT protocol used in a standard publisher-broker-subscriber configuration provided by Eclipse Mosquitto. More specifically, we compare the performance penalty on the protocol when securing communications with TLS following a monolithic implementation and with CMXsafe. The experimental results suggest that CMXsafe outperforms integrated security by providing at least a 25% latency reduction and a 22% bandwidth improvement.
David de Hoz, Taous Madi, Charalambos Konstantinou
IEEE Trans. Inf. Forensics Secur.3
2023 Decentralizing Cyber Physical Systems for Resilience: An Innovative Case Study from A Cybersecurity Perspective
Xueping Liang, Charalambos Konstantinou, Sachin Shetty, Eranga Bandara, Ruimin Sun
Comput. Secur.2
2023 A Triggerless Backdoor Attack and Defense Mechanism for Intelligent Task Offloading in Multi-UAV Systems
abstract
In recent years, multiunmanned aerial vehicular systems (MUAVs) have become prevalent in divergent applications: agriculture, spectrum utilization, transportation, forest fire monitoring, and among others, due to their flexible, robust, and autonomous operational maneuver. Battery-powered multiunmanned aerial vehicles (MUAVs) systems possess limited computation and communication resources, significantly reducing their functional dimension by limiting mission time and range. To address this issue, we propose a federated deep reinforcement learning (FDRL)-based intelligent and decentralized task offloading scheme for resource-constrained UAVs that can enhance the operational capability of the MUAV systems. Moreover, the proposed FDRL scheme can improve offloading policy quality while preserving data privacy in MUAV. However, such intelligent systems may fall prey to backdoor attacks that can intervene in the system’s regular operation causing rapid degradation of its performance. We introduce a novel triggerless backdoor attack scheme on intelligent task offloading UAVs and analyze its impact to gauge the resiliency of the offloading policy in the presence of an adversary. Then, we propose lightweight agnostic defense mechanisms to combat such backdoors in multi-UAV settings. The extensive simulation results show that the proposed attack and defense strategies are practical and efficient.
Shafkat Islam, Shahriar Badsha, Ibrahim Khalil 0001, Mohammed Atiquzzaman, Charalambos Konstantinou
IEEE Internet Things J.5
2023 CPES-QSM: A Quantitative Method Toward the Secure Operation of Cyber-Physical Energy Systems
abstract
Power systems are evolving into cyber–physical energy systems (CPES) mainly due to the integration of modern communication and Internet of Things (IoT) devices. CPES security evaluation is challenging since the physical and cyber layers are often not considered holistically. Existing literature focuses on only optimizing the operation of either the physical or cyber layer while ignoring the interactions between them. This article proposes a metric, the cyber–physical energy system quantitative security metric (CPES-QSM), that quantifies the interaction between the cyber and physical layers across three domains: 1) electrical; 2) cyber-risk; and 3) network topology. A method for incorporating the proposed cyber-metric into operational decisions is also proposed by formulating a cyber-constrained ac optimal power flow (C-ACOPF) that considers the status of all the CPES layers. The C-ACOPF considers the vulnerabilities of physical and cyber networks by incorporating factors such as voltage stability, contingencies, graph theory, and IoT cyber risks, while using a multicriteria decision-making technique. Simulation studies are conducted using standard IEEE test systems to evaluate the effectiveness of the proposed metric and the C-ACOPF formulation.
Juan Ospina, Venkatesh Venkataramanan, Charalambos Konstantinou
IEEE Internet Things J.3
2023 Blockchain for unmanned underwater drones: Research issues, challenges, trends and future directions
Neelu Jyothi Ahuja, Monika Thapliyal, Sarthika Dutt, Tanesh Kumar, Diego Augusto de Jesus Pacheco, Charalambos Konstantinou, Kim-Kwang Raymond Choo
J. Netw. Comput. Appl.7
2023 A Secure and Trusted Mechanism for Industrial IoT Network Using Blockchain
abstract
Industrial Internet-of-Things (IIoT) is a powerful IoT application, which remodels the growth of industries by ensuring transparent communication among various entities such as hubs, manufacturing places, and packaging units. Introducing data science techniques within the IIoT improves the ability to analyze the collected data in a more efficient manner, which current IIoT architectures lack due to their distributed nature. From a security perspective, network anomalies/attackers pose high security risk in IIoT. In this article, we have addressed this problem, where a coordinator IoT device is elected to compute the trust of IoT devices to prevent the MD to be part of network. Further, the transparency of the data is ensured by integrating a blockchain-based data model. The performance of the proposed framework is validated extensively and rigorously via MATLAB against various security metrics such as attack strength, message alteration, and probability of false authentication. The simulation results suggest that the proposed solution increases IIoT network security by efficiently detecting malicious attacks in the network.
Geetanjali Rathee, Naveen Jaglan, Charalambos Konstantinou
IEEE Trans. Ind. Informatics4
2023 Agreement-Induced Data Verification Model for Securing Vehicular Communication in Intelligent Transportation Systems
abstract
Intelligent Transportation security requires cooperative credentials for sharing navigation and communication data between the vehicles. However due to the dynamic environment, communication is interrupted by the adversaries, resulting in non-privacy issues. This article introduces an Agreement-induced Data Verification Model (ADVM) for securing vehicular communication against adversaries. The connected vehicles in a grid communicate with each other based on direct and indirect recommendation. This recommendation is based on mutual identity sharing between the vehicles for masked information exchange. Non-replicated and recommendation based verifications are performed using the vector classification learning. In this learning process, the credential validity and communication tolerance amid adversaries are augmented. The constraint-failing vehicles are disconnected from the communication grid, preventing its insecure impact over the communication. The proposed model’s performance is verified using false rate, success ratio, processing time, complexity, and recommendation ratio. For the different vehicles, the proposed model achieves 9.69% less false rate, 10.3% success ratio, 10.49% less processing time, 10.3% less complexity, and 12.87% high recommendation ratio.
Priyan Malarvizhi Kumar, Charalambos Konstantinou, Shakila Basheer, Gunasekaran Manogaran, Bharat S. Rawal, Gokulnath Chandra Babu
IEEE Trans. Intell. Transp. Syst.2
2022 An IoT Digital Twin for Cyber-Security Defence Based on Runtime Verification
David de Hoz, Anastasios Temperekidis, Panagiotis Katsaros, Charalambos Konstantinou
ISoLA (1)4
2022 Datadriven false data injection attacks against cyber-physical power systems
Jiwei Tian, Buhong Wang, Charalambos Konstantinou
Comput. Secur.4
2022 Consumer, Commercial, and Industrial IoT (In)Security: Attack Taxonomy and Case Studies
abstract
Internet of Things (IoT) devices are becoming ubiquitous in our lives, with applications spanning from theconsumerdomain tocommercialandindustrialsystems. The steep growth and vast adoption of IoT devices reinforce the importance of sound and robust cybersecurity practices during the device development life cycles. IoT-related vulnerabilities, if successfully exploited can affect, not only the device itself but also the application field in which the IoT device operates. Evidently, identifying and addressing every single vulnerability are an arduous, if not impossible, task. Attack taxonomies can assist in classifying attacks and their corresponding vulnerabilities. Security countermeasures and best practices can then be leveraged to mitigate threats and vulnerabilities before they emerge into catastrophic attacks and ensure overall secure IoT operation. Therefore, in this article, we provide an attack taxonomy, which takes into consideration the different layers of the IoT stack, i.e., device, infrastructure, communication, and service, and each layer’s designated characteristics, which can be exploited by adversaries. Furthermore, using nine real-world cybersecurity incidents that had targeted IoT devices deployed in the consumer, commercial, and industrial sectors, we describe the IoT-related vulnerabilities, exploitation procedures, attacks, impacts, and potential mitigation mechanisms and protection strategies. These (and many other) incidents highlight the underlying security concerns of IoT systems and demonstrate the potential attack impacts of such connected ecosystems, while the proposed taxonomy provides a systematic procedure to categorize attacks based on the affected layer and corresponding impact.
Christos Xenofontos, Ioannis Zografopoulos, Charalambos Konstantinou, Alireza Jolfaei, Muhammad Khurram Khan, Kim-Kwang Raymond Choo
IEEE Internet Things J.3
2022 A Modular End-to-End Framework for Secure Firmware Updates on Embedded Systems
abstract
Firmware refers to device read-only resident code which includes microcode and macro-instruction -level routines. For Internet-of-Things (IoT) devices without an operating system, firmware includes all the necessary instructions on how such embedded systems operate and communicate. Thus, firmware updates are an essential part of device functionality. They provide the ability to patch vulnerabilities, address operational issues, and improve device reliability and performance during the lifetime of the system. This process, however, is often exploited by attackers in order to inject malicious firmware code into the embedded device. In this paper, we present a framework for secure firmware updates on embedded systems. The approach is based on hardware primitives and cryptographic modules, and it can be deployed in environments where communication channels might be insecure. The implementation of the framework is flexible as it can be adapted in regards to the IoT device's available hardware resources and constraints. Our security analysis shows that our framework is resilient to a variety of attack vectors. The experimental setup demonstrates the feasibility of the approach. By implementing a variety of test cases on FPGA, we demonstrate the adaptability and performance of the framework. Experiments indicate that the update procedure for a 1183kB firmware image could be achieved, in a secure manner, under 1.73 seconds.
Solon Falas, Charalambos Konstantinou, Maria K. Michael
ACM J. Emerg. Technol. Comput. Syst.2
2022 Resilient Cyber-Physical Energy Systems Using Prior Information Based on Gaussian Process
abstract
The power grid infrastructure is a large-scale, heterogeneous, and complex cyber-physical system, which forms the lifeline of modern societies. The trend of tight coupling of physics, communication, and computation in cyber-physical energy systems (CPESs) is evident by the inclusion of numerous measurement sensors. This contributes to enhancing the monitoring and control functionalities of CPESs. At the same time, the occurrence of adverse effects constitutes a vital dimension of CPES operation. Increasing the resilience of critical energy systems is of key importance for safeguarding the national economy and security. This article considers the problem of optimal estimation with sensing measurements subject to arbitrary corruption resulting from adverse effects. Such signals can cause false situation awareness and/or trigger a sequence of cascading effects leading to an ultimate system failure. We formulate the problem as a constrained optimization with additional prior information posed as a set inclusion constraint on the measurement vector. It is shown that if the prior set satisfies certain conditions, the resulting recovery error bound is improved. The approach demonstrates enhancement of the CPES resiliency by using the Gaussian process as the basis of a prior generative probabilistic regression model using historical data. The validation of the resiliency mechanism using prior information is performed using the New York Independent System Operator grid data, demonstrating 100% successful state recovery for up to 60% of CPES sensor failures.
Charalambos Konstantinou, Olugbenga Moses Anubi
IEEE Trans. Ind. Informatics1
2022 Detection of Malicious Attacks in Autonomous Cyber-Physical Inverter-Based Microgrids
abstract
The distributed generation capabilities of microgrids (MGs) arise as essential assets in enhancing grid resilience. The integration of distributed energy sources, controllable loads, and prosumers necessitates the deployment of potent control and communication synergies. While those synergies transform MGs into cyber-physical systems through information technologies able to sense, control, and actuate local resources and loads, they inadvertently expose MGs to cyber-attack threats. Increasing the security of critical communication and control systems against “black swan” events, i.e., high-impact low-probability cyber-physical incidents, is a major priority for MG operations. Such incidents, if left unabated, can intensify and elicit system dynamics instability, eventually causing outages and system failures. In this article, we develop an integrated approach for multiagent MG systems able to perform the detection of malicious cyber-physical attacks based on subspace methods. We employ the small-signal model of an autonomous/islanded MG and consider different attack models targeting the MG’s secondary frequency control. The attack detector is constructed via identifying the stable kernel representation of the autonomous cyber-physical MG in the attack-free case. We illustrate the impact of the attack models as well as the feasibility of the developed detection method in simulation models of the Canadian urban benchmark distribution system.
Ioannis Zografopoulos, Charalambos Konstantinou
IEEE Trans. Ind. Informatics2
2020 Special Session: Physics- Informed Neural Networks for Securing Water Distribution Systems
abstract
Physics-informed neural networks (PINNs) is an emerging category of neural networks which can be trained to solve supervised learning tasks while taking into consideration given laws of physics described by general nonlinear partial differential equations. PINNs demonstrate promising characteristics such as performance and accuracy using minimal amount of data for training, utilized to accurately represent the physical properties of a system's dynamic environment. In this work, we employ the emerging paradigm of PINNs to demonstrate their potential in enhancing the security of intelligent cyberphysical systems. In particular, we present a proof-of-concept scenario using the use case of water distribution networks, which involves an attack on a controller in charge of regulating a liquid pump through liquid flow sensor measurements. PINNs are used to mitigate the effects of the attack while demonstrating the applicability and challenges of the approach.
Solon Falas, Charalambos Konstantinou, Maria K. Michael
ICCD2
2020 Special Session: Harness the Power of DERs for Secure Communications in Electric Energy Systems
abstract
Electric energy systems are undergoing significant changes to improve system reliability and accommodate increasing power demands. The penetration of distributed energy resources (DERs) including roof-top solar panels, energy storage, electric vehicles, etc., enables the on-site generation of economically dispatchable power curtailing operational costs. The effective control of DERs requires communication between utilities and DER system operators. The communication protocols employed for DER management and control lack sophisticated cybersecurity features and can compromise power systems secure operation if malicious control commands are issued to DERs. To overcome authentication-related protocol issues, we present a bolt-on security extension that can be implemented on Distributed Network Protocol v3 (DNP3). We port an authentication framework, DERauth, into DNP3, and utilize real-time measurements from a simulated DER battery energy storage system to enhance communication security. We evaluate our framework in a testbed setup using DNP3 master and outstation devices performing secure authentication by leveraging the entropy of DERs.
Ioannis Zografopoulos, Juan Ospina, Charalambos Konstantinou
ICCD3
2020 Enhanced Resilient State Estimation Using Data-Driven Auxiliary Models
abstract
This paper considers the problem of resiliency in the state estimation of a cyber-physical system when a portion of its sensor measurements contains malicious data added by an adversarial attacker. When the attack consists of arbitrary random uncorrelated data injection, compressive-sensing-based regression algorithms that can recover the true states have been studied extensively in the literature. However, it has been shown that it is possible to create a targeted correlated false data injection attack (FDIA), which will fool any regression-based algorithm. Consequently, there have been a plethora of data-driven approaches investigated to detect the occurrence of such an FDIA. This paper combines a data-driven model with the traditional compressive sensing regression problem. It is shown that the solution of the resulting constrained optimization problem recovers the true states of the system. The developed algorithm is evaluated through a numerical simulation example of the IEEE 14-bus system mapped to the New York Independent System Operator grid data.
Olugbenga Moses Anubi, Charalambos Konstantinou
IEEE Trans. Ind. Informatics2
2019 A Hardware-based Framework for Secure Firmware Updates on Embedded Systems
abstract
The ability to update firmware in embedded systems allows end-users to patch device vulnerabilities and improve functionality. However, this process is often exploited by adversaries in order to inject malicious firmware code into embedded devices. In this paper, we present a framework which enables highly secure and fast firmware update delivery with minimal downtime on embedded devices. The proposed framework utilizes device intrinsic physical characteristics to authenticate firmware packages along with integrated cryptographic modules to ensure the firmware confidentiality and integrity. A proof-of-concept design is implemented on FPGA, which demonstrates high performance with reasonable overheads, while our analysis shows strong security guarantees.
Solon Falas, Charalambos Konstantinou, Maria K. Michael
VLSI-SoC2
2018 PHYLAX: Snapshot-based profiling of real-time embedded devices via JTAG interface
abstract
Real-time embedded systems play a significant role in the functionality of critical infrastructure. Legacy microprocessor-based embedded systems, however, have not been developed with security in mind. Applying traditional security mechanisms in such systems is challenging due to computing constraints and/or real-time requirements. Their typical 20-30 year lifespan further exacerbates the problem. In this work, we propose PHYLAX, a plug-and-play solution to detect intrusions in already installed embedded devices. PHYLAX is an external monitoring tool which does not require code instrumentation. Also, our tool adapts and prioritizes intrusion detection based on the requirements of the underlying infrastructure (power grid, chemical factory, etc.) as well as the computing capabilities of the target embedded system (CPU model, memory size, etc.). PHYLAX can be employed on any legacy device which incorporates a JTAG interface. As a case study, we present the inclusion of PHYLAX on a power grid recloser controller.
Charalambos Konstantinou, Eduardo Chielle, Michail Maniatakos
DATE1
2018 Low-budget Energy Sector Cyberattacks via Open Source Exploitation
abstract
Modern cyber warfare involves penetration of a nation's computers and networks, aiming to cause extensive damage and/or disruption. Such actions are generally deemed feasible only by resource-wealthy nation state actors. In this work, we challenge this perception and introduce a methodology dubbed Open Source Exploitation (OSEXP), which leverages public infrastructure to execute an advanced cyber attack on critical infrastructure. In particular, we characterize and verify an effective and reusable OSEXP attack vector based on time spoofing of Global Positioning System (GPS) signals. Our GPS attack employs commercial devices and open source software, and manipulates the time synchronization of carefully selected power grid equipment in a manner that can lead to large scale blackouts. We experimentally verify the feasibility of our GPS OSEXP methodology, and demonstrate that an actor with limited budget has the ability to cause significant disruption to a nation.
Anastasis Keliris, Charalambos Konstantinou, Marios Sazos, Michail Maniatakos
VLSI-SoC2
2016 Enabling multi-layer cyber-security assessment of Industrial Control Systems through Hardware-In-The-Loop testbeds
abstract
Industrial Control Systems (ICS) are under modernization towards increasing efficiency, reliability, and controllability. Despite the numerous benefits of interconnecting ICS components, the wide adoption of Information Technologies (IT) has introduced new security challenges and vulnerabilities to industrial processes, previously obscured by the systems' custom designs. Towards securing the backbone of critical infrastructure, selection of the proper assessment environment for performing cyber-security assessments is crucial. In this paper, we present a layered analysis of vulnerabilities and threats in ICS components, that identifies the need for including real hardware components in the assessment environment. Moreover, we advocate the suitability of Hardware-In-The-Loop testbeds for ICS cyber-security assessment and present their advantages over other assessment environments.
Anastasis Keliris, Charalambos Konstantinou, Nektarios Georgios Tsoutsos, Raghad Baiad, Michail Maniatakos
ASP-DAC2
2016 The Cybersecurity Landscape in Industrial Control Systems
abstract
Industrial control systems (ICSs) are transitioning from legacy-electromechanical-based systems to modern information and communication technology (ICT)-based systems creating a close coupling between cyber and physical components. In this paper, we explore the ICS cybersecurity landscape including: 1) the key principles and unique aspects of ICS operation; 2) a brief history of cyberattacks on ICS; 3) an overview of ICS security assessment; 4) a survey of “uniquely-ICS” testbeds that capture the interactions between the various layers of an ICS; and 5) current trends in ICS attacks and defenses.
Stephen McLaughlin 0003, Charalambos Konstantinou, Lucas Davi, Ahmad-Reza Sadeghi, Michail Maniatakos, Ramesh Karri
Proc. IEEE2
2015 Privacy-preserving functional IP verification utilizing fully homomorphic encryption
Charalambos Konstantinou, Anastasis Keliris, Michail Maniatakos
DATE1
2015 Cyber-physical systems: A security perspective
abstract
A cyber-physical system (CPS) is a composition of independently interacting components, including computational elements, communications and control systems. Applications of CPS institute at different levels of integration, ranging from nation-wide power grids, to medium scale, such as the smart home, and small scale, e.g. ubiquitous health care systems including implantable medical devices. Cyber-physical systems primarily transmute how we interact with the physical world, with each system requiring different levels of security based on the sensitivity of the control system and the information it carries. Considering the remarkable progress in CPS technologies during recent years, advancement in security and trust measures is much needed to counter the security violations and privacy leakage of integration elements. This paper focuses on security and privacy concerns at different levels of the composition and presents system level solutions for ensuring the security and trust of modern cyber-physical systems.
Charalambos Konstantinou, Michail Maniatakos, Fareena Saqib, Shiyan Hu 0001, James F. Plusquellic, Yier Jin
ETS1
2015 ConFirm: Detecting Firmware Modifications in Embedded Systems using Hardware Performance Counters
abstract
Critical infrastructure components nowadays use microprocessor-based embedded control systems. It is often infeasible, however, to employ the same level of security measures used in general purpose computing systems, due to the stringent performance and resource constraints of embedded control systems. Furthermore, as software sits atop and relies on the firmware for proper operation, software-level techniques cannot detect malicious behavior of the firmware. In this work, we propose ConFirm, a low-cost technique to detect malicious modifications in the firmware of embedded control systems by measuring the number of low-level hardware events that occur during the execution of the firmware. In order to count these events, ConFirm leverages the Hardware Performance Counters (HPCs), which readily exist in many embedded processors. We evaluate the detection capability and performance overhead of the proposed technique on various types of firmware running on ARM- and PowerPC-based embedded processors. Experimental results demonstrate that ConFirm can detect all the tested modifications with low performance overhead.
Charalambos Konstantinou, Michail Maniatakos, Ramesh Karri
ICCAD2
2014 Advanced Techniques for Designing Stealthy Hardware Trojans
abstract
The necessity of detecting malicious modifications in hardware designs has led to the development of various detection tools. Trojan detection approaches aim to reveal compromised designs using several methods such as static code analysis, side-channel dynamic signal analysis, design for testing, verification, and monitoring architectures etc. This paper demonstrates new approaches for circumventing some of the latest Trojan detection techniques. We introduce and implement stealthy Trojans designs that do not violate the functional specifications of the corresponding original models. The designs chosen to demonstrate the effectiveness of our techniques correspond to encryption algorithms and a pseudo random number generator. The proposed Trojans are inserted into the original RTL, and decrease the overall security of the designs, minimizing detection probability by state-of-the-art static analysis tools.
Nektarios Georgios Tsoutsos, Charalambos Konstantinou, Michail Maniatakos
DAC2