Model-Based Run-Time Cybersecurity: Combining Software and Hardware Monitoring for Robust Intrusion Detection
A new paper on arXiv (2608.11802) proposes a model-based approach to enhance run-time cybersecurity by integrating software- and hardware-based monitoring. The method aims to improve intrusion detection and attack identification by making it harder for attackers to camouflage their activities. The paper outlines an architecture where software-level observation flags suspicious activities, which are then independently verified by hardware-level monitoring. This dual-layer approach addresses vulnerabilities in traditional control-flow monitoring, which can be manipulated by attackers to evade detection. The research highlights the increasing importance of system resilience against cyber-attacks and offers a more robust framework for anomaly detection and attack identification.
Key facts
- The paper is titled 'Towards Model-based Run-time Cybersecurity: On Control-Flow Anomaly Detection, Attack Identification, and Hardware Monitoring'.
- It is available on arXiv with identifier 2608.11802.
- The paper proposes a model-based approach combining software- and hardware-based monitoring.
- Software-level observation indicates suspicious activities, while hardware-level monitoring checks them in more detail.
- The approach aims to make it harder for attacks to camouflage themselves and go undetected.
- Traditional control-flow monitoring is vulnerable to camouflage by attackers.
- Attack trees are used to identify possible types of attacks once anomalies are detected.
- The paper outlines an architecture that combines software- and hardware-based monitoring for more robust intrusion detection.
Entities
—