SBIR-STTR Award

Runtime Lightweight Hardware-Assisted Machine Learning-based Cyber Attack Detection
Award last edited on: 8/12/2023

Sponsored Program
SBIR
Awarding Agency
DHS
Total Award Amount
$149,972
Award Phase
1
Solicitation Topic Code
DHS231-001
Principal Investigator
Setareh Rafatirad

Company Information

9 Corner Solutions LLC

13645 Dulles Technology Drive
Herndon, VA 20171
   (470) 495-8473
   N/A
   www.9csol.com
Location: Single
Congr. District: 11
County: Fairfax

Phase I

Contract Number: 70RSAT23C00000020
Start Date: 5/9/2023    Completed: 10/8/2023
Phase I year
2023
Phase I Amount
$149,972
The grand vision of the Internet-of-Things (IoT) boasts a fully connected, global network of devices or systems connecting every imaginable thing. Amelioration of miniature embedded computing devices into the consumer and industrial markets with enabled connectivity to the Internet towards smart and intelligent features leads to an upsurge in the size of networks through which they are linked and communicate. Unfortunately, with the massive amount of potential benefits offered by IoT devices comes an equal amount of potential vulnerabilities and cyber-threats including such as Malware, ransomware, and distributed denial-of-service (DDoS) attacks. Detection and defense of cyber-threats in IoT devices are traditionally performed by anti-virus (AV) software. However, AV-based threat detection has significant setbacks including large latency, processing overheads, inability to effectively detect zero-day attacks, and requirement of frequent updates. In this project, we propose the design of hardware-assisted runtime cyber-threat detection. We employ hardware-generated microarchitectural event traces captured through hardware performance counter (HPC) register information to extract the application characteristics to detect cyber-threats. To minimize overheads and facilitate runtime feasibility, an automated learning-based optimal feature extraction is designed. These features are fed to a lightweight machine learning (ML) classifier to detect the feasibility of the presence of cyber-threat. This is complemented with a specialized ML classifier in the second stage for enhanced performance. The second stage ML classifier also employs a time-series-based anomaly detection for zero-day and unseen threat detection. The portability of the proposed solution across different architectures and vendors enables commercialization seamlessly.

Phase II

Contract Number: ----------
Start Date: 00/00/00    Completed: 00/00/00
Phase II year
----
Phase II Amount
----