• DocumentCode
    3762205
  • Title

    Detection of x86 malware in AMI data payloads

  • Author

    Vignesh Babu;David M. Nicol

  • Author_Institution
    Information Trust Institute, University of Illinois at Urbana Champaign, Urbana, IL-USA
  • fYear
    2015
  • Firstpage
    617
  • Lastpage
    622
  • Abstract
    Malware can spread uncontrollably if left unchecked and can cause significant damage to the Advanced Metering Infrastructure (AMI) and ultimately to the underlying power grid. Application layer protocols used in the AMI are capable of carrying large payloads which could be potentially used to hide malware. Fortunately, application layer traffic in the AMI is not expected to contain executable content and hence the problem of malware detection in data payloads simply changes to the problem of executable content detection. In this paper, we propose a policy engine implementation which sits between the network and application layers and performs comprehensive syntactic and semantic rule checks on each received packet and for the presence of encryption, ARM or x86 executable content. The policy engine is integrated with the C12.22 protocol library and is primarily targeted for deployment in head end systems.
  • Keywords
    "Malware","Data transfer","Protocols","Smart grids","Payloads","Engines","Software"
  • Publisher
    ieee
  • Conference_Titel
    Smart Grid Communications (SmartGridComm), 2015 IEEE International Conference on
  • Type

    conf

  • DOI
    10.1109/SmartGridComm.2015.7436369
  • Filename
    7436369