Hardware Support for Automated Proactive Defenses
Open Access DepositedThe rapid evolution of cyberattacks necessitates continuous advancements in computer system defenses. Traditional software-based proactive defenses often fall short due to their reactive nature, high performance overheads, and susceptibility to tampering. This dissertation addresses these limitations by exploring novel hardware-supported automated proactive defense frameworks. Leveraging hardware for security offers significant advantages over software, including increased system performance, strong isolation from malicious software, and tamper resistance. This work first introduces a suite of innovative hardware designs—Mayavi, Mayalok, and Maya—that integrate into the processor pipeline to deceive and misdirect attackers at the instruction-level with minimal performance impact. Mayavi manipulates malicious memory accesses to redirect malware to deceptive honeypots. Mayalok employs runtime instruction infusion to present a falsified system view, confusing and misleading attackers. Maya provides hardware support for instruction manipulation at the user-kernel interface, activating lightweight subroutines to dynamically alter malware behavior. These techniques effectively disrupt an attacker's actions and provide valuable insights into their behavior. Building on these foundational primitives, this work proposes Epic, a comprehensive proactive defense framework with a precise instruction manipulation engine that provides fine-grained control over program execution. Finally, to achieve true autonomy, the dissertation presents hardware-based defenses orchestrated by a deep reinforcement learning (DRL) agent. This DRL agent learns to anticipate, mitigate, and respond to cyber threats in real-time by observing application behavior, dynamically triggering user-defined subroutines to neutralize potential damage from malware. The effectiveness of these frameworks is rigorously evaluated using architectural simulators and standardized benchmarks. Our results demonstrate that proactive defenses leveraging the proposed hardware modifications can effectively protect sensitive resources against a diverse range of attack vectors, including ransomware, info-stealers, and timing side-channel attacks. This is achieved while incurring minimal performance overhead compared to traditional software-only approaches. Attacker-defender simulations further highlight the superiority of our hardware-supported strategies over alternative techniques. The DRL agent's performance is also evaluated, with experimental results showing it can learn an effective defense policy faster than prior approaches. Ultimately, this dissertation advances the field of automated proactive cyber defenses by demonstrating the potential of hardware support to enhance performance, scalability, and security. The primary contributions are the design and implementation of novel hardware-assisted frameworks, their rigorous evaluation against diverse attack vectors, and the insights gained into the benefits of hardware-based, automated defense mechanisms.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.
| Thumbnail | Title | Date Uploaded | Visibility | Actions |
|---|---|---|---|---|
|
|
Derasari_gwu_0075A_17570.pdf | 2025-12-11 | Open Access |
|