ARTFEED — Contemporary Art Intelligence

Model-Based Run-Time Cybersecurity: Combining Software and Hardware Monitoring for Robust Intrusion Detection

other · 2026-08-13

A new paper on arXiv (2608.11802) proposes a model-based approach to enhance run-time cybersecurity by integrating software- and hardware-based monitoring. The method aims to improve intrusion detection and attack identification by making it harder for attackers to camouflage their activities. The paper outlines an architecture where software-level observation flags suspicious activities, which are then independently verified by hardware-level monitoring. This dual-layer approach addresses vulnerabilities in traditional control-flow monitoring, which can be manipulated by attackers to evade detection. The research highlights the increasing importance of system resilience against cyber-attacks and offers a more robust framework for anomaly detection and attack identification.

Key facts

  • The paper is titled 'Towards Model-based Run-time Cybersecurity: On Control-Flow Anomaly Detection, Attack Identification, and Hardware Monitoring'.
  • It is available on arXiv with identifier 2608.11802.
  • The paper proposes a model-based approach combining software- and hardware-based monitoring.
  • Software-level observation indicates suspicious activities, while hardware-level monitoring checks them in more detail.
  • The approach aims to make it harder for attacks to camouflage themselves and go undetected.
  • Traditional control-flow monitoring is vulnerable to camouflage by attackers.
  • Attack trees are used to identify possible types of attacks once anomalies are detected.
  • The paper outlines an architecture that combines software- and hardware-based monitoring for more robust intrusion detection.

Entities

Sources