Windows 10: Scientists Working On CPU That Can Detect Malware At Hardware Level

Discus and support Scientists Working On CPU That Can Detect Malware At Hardware Level in AntiVirus, Firewalls and System Security to solve the problem; Source: Scientists Working on a CPU That Can Detect Malware at the Hardware Level Researchers are working on a new CPU chip design that will extend... Discussion in 'AntiVirus, Firewalls and System Security' started by RubberDucky, Nov 10, 2016.

  1. Scientists Working On CPU That Can Detect Malware At Hardware Level


    Source: Scientists Working on a CPU That Can Detect Malware at the Hardware Level

    Researchers are working on a new CPU chip design that will extend the fight against malware at the hardware level in an attempt to bolster computers, mobiles, and other devices against the rising wave of security threats.

    The work is being carried out by two teams of researchers from the Binghamton University and the University of California-Riverside.

    The project is named "Practical Hardware-Assisted Always-On Malware Detection" and will be funded through a three-year research grant of $275,000 the teams received from the National Science Foundation.

    New chip design to detect process anomalies inside the CPU
    The principle at the base of this research is to modify a CPU chip to include extra logic to detect anomalies in running processes. Once something out of order is detected, the CPU will alert local security software that something is wrong. The local security software will have the final decision on what to do with the detected anomaly.

    Researchers are sceptic that the modified CPU will pick up all threats, but they view their project as an extra layer of defense they can add to CPUs, and not as a standalone security system.

    Scientists say that the CPU will use low complexity machine learning algorithms to classify malware from normal processes.

    "The detector is, essentially, like a canary in a coal mine to warn software programs when there is a problem," said Dmitry Ponomarev, professor of computer science at Binghamton University, State University of New York.

    "The hardware detector is fast, but is less flexible and comprehensive. The hardware detector’s role is to find suspicious behavior and better direct the efforts of the software," Prof. Ponomarev also added.

    Previous work on this topic
    The work of Prof. Ponomarev and his team is not unique. In 2014, a team of three researchers from the Columbia University in New York, have also explored the subject in their paper titled "Unsupervised Anomaly-based Malware Detection using Hardware Features."

    In their work, the Columbia team used a similar system to the one proposed by the Binghamton and California-Riverside researchers. The Columbia team used unsupervised machine learning to build profiles of normal program execution based on data from performance counters and used these profiles to detect significant deviations in program behavior that occurred as a result of malware exploitation attempts.

    Similar work has been carried out by Intel and researchers from Clarkson University. The work of the Binghamton researcher team, on which this project is based, is detailed in research papers titled "Hardware-based Malware Detection using Low-level Architectural Features" and "Ensemble Learning for Low-level Hardware-supported Malware Detection."

    In recent months, news about CPUs and security involved researchers bypassing ASLR protections on Intel Haswell CPUs or researchers finding hidden code (some would call it a backdoor) inside the architecture of Intel x86 processors. In fact, two of the researchers working on this project, were also on the team that discovered the Intel Haswell CPU ASLR bypass technique.

    :)
     
    RubberDucky, Nov 10, 2016
    #1

  2. Will Windows 10 NEW Version (April, 2017) have an improved version of Windows defender?

    It is not about creator update or future release but Microsoft Anti-Malware team keep working to improve Anti-Malware engine regularly. From personal experience and observing real scenario of using Anti-Malware products including Windows Defender. It is
    doing great job and it has high level of satisfaction and remember there is no Anti-Virus program capable of detecting and removing all malwares, but you need to set a right policy and report files which might not be detected with Windows Defender.
     
    Cyber_Defend_Team, Nov 10, 2016
    #2
  3. Abram730 Win User
    Windows 10 compatibility checker CPU not supported??

    Windows 8 and Windows 8.1 also can't detect the frequencies of Memory or CPU's. It's not just the app.

    Windows think my CPU's max frequency is 0.80 GHz if I change the boost clock multiplier from 39 to 42. Any Intel CPU with a "K" at the end has an unlocked multiplier. That is can be overclocked.

    This is something Microsoft needs to fix. Overclocking is a thing and Windows should be able to detect clock frequencies. Every other piece of software for detecting hardware seems to work just fine. Why is Microsoft the only ones that can't handle it.
    It's an OS's job to handle hardware and Microsoft not being able to hand simple tasks like detecting clock frequencies or being able to tell the difference between the words minimum and maximum, doesn't instill confidence in their ability to make a functional OS.
     
    Abram730, Nov 10, 2016
    #3
  4. Scientists Working On CPU That Can Detect Malware At Hardware Level

    Thanks, RubberDucky!

    Good news!!

    Hope they can pull it off.
     
    cottonball, Nov 11, 2016
    #4
  5. eLPuSHeR Win User
    It sounds very difficult to achieve but I hope they succeed.
     
    eLPuSHeR, Nov 11, 2016
    #5
  6. jimbo45 Win User
    Hi there

    Possibly a bit of a waste of money IMO -- what is actually "A threat" -- what happens if the hardware thinks something is bad but it's actually OK (there's enough trouble with current AV software with False positive warnings).

    Getting a grant for this type of stuff is like getting a grant of 100,000's of dollars to verify that people getting drunk at weekends in city centres are more likely to cause trouble than people staying at home !!!.

    Money IMO would be better spent on training USERS to use computers more sensibly and avoid obvious risks like opening email links from unknown senders, giving out too much data on social media or opening fake web sites purporting to be from Banks / Police / Tax authorities etc.

    I'm all for progress but this IMO as a 100% waste of money. Sounds like a typical Govt or public sector idea.

    Has reminders about US Federal Govt paying well over the odds for Toilet seats for the military and zillions of other similar projects. - Not only US federal Govt but almost any public sector contract worldwide !!!!.

    Cheers
    jimbo
     
    jimbo45, Nov 12, 2016
    #6
  7. eLPuSHeR Win User
    I think Jimbo is utterly right on this regard.
     
    eLPuSHeR, Apr 5, 2018
    #7
Thema:

Scientists Working On CPU That Can Detect Malware At Hardware Level

Loading...
  1. Scientists Working On CPU That Can Detect Malware At Hardware Level - Similar Threads - Scientists Working CPU

  2. False malware detection

    in AntiVirus, Firewalls and System Security
    False malware detection: Good evening,My Windows 10 keeps identifying a perfectly legitimate program, Praat, as malware. Praat has been used by linguists and others that desire sonograms of human speech for decades. It is some of the best software available on any platform for acoustic analysis...
  3. False malware detection

    in Windows 10 Gaming
    False malware detection: Good evening,My Windows 10 keeps identifying a perfectly legitimate program, Praat, as malware. Praat has been used by linguists and others that desire sonograms of human speech for decades. It is some of the best software available on any platform for acoustic analysis...
  4. False malware detection

    in Windows 10 Software and Apps
    False malware detection: Good evening,My Windows 10 keeps identifying a perfectly legitimate program, Praat, as malware. Praat has been used by linguists and others that desire sonograms of human speech for decades. It is some of the best software available on any platform for acoustic analysis...
  5. Can Windows Defender detected malware thats stopped working?

    in AntiVirus, Firewalls and System Security
    Can Windows Defender detected malware thats stopped working?: So im having problems with my Edge browser and when i turned it off it stopped to happening. You can read my problem here: https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/problem-with-edge/bf30c8ed-0494-4edb-87ec-7e89df95e34bAnd...
  6. affinity level CPU

    in Windows 10 Gaming
    affinity level CPU: I have a program that starts running too much CPU usage. The last time this program did this it was on an over the top 36 core something or other laptop, I like to call it the Unicorn laptop. To solve the issue I set the affinity level down to 8 cores from task manager...
  7. affinity level CPU

    in Windows 10 Software and Apps
    affinity level CPU: I have a program that starts running too much CPU usage. The last time this program did this it was on an over the top 36 core something or other laptop, I like to call it the Unicorn laptop. To solve the issue I set the affinity level down to 8 cores from task manager...
  8. affinity level CPU

    in Windows 10 Customization
    affinity level CPU: I have a program that starts running too much CPU usage. The last time this program did this it was on an over the top 36 core something or other laptop, I like to call it the Unicorn laptop. To solve the issue I set the affinity level down to 8 cores from task manager...
  9. Defender detected malware

    in AntiVirus, Firewalls and System Security
    Defender detected malware: Hi,in my environment the file 7zG.exe got deployed automatically to 100+ devices not manually or not from SCCM- not sure how it got deployed the defender has detected malware in it due to this, we have received 100+ alert generated for the same and still continuing.does this...
  10. Malware or Hardware Defect or both?

    in AntiVirus, Firewalls and System Security
    Malware or Hardware Defect or both?: Hello Everyone, This is my System: HP ProBook 470 G5 Intel Core i7-8550U CPU 16 GB RAM Windows 10 Pro Version 1903 OS Build 18362.836 Windows Defender Security intelligence version 1.317.1305.0 Intel UHD Graphics 620 Version 27.20.100.8280 I have been...