DocumentCode
3762205
Title
Detection of x86 malware in AMI data payloads
Author
Vignesh Babu;David M. Nicol
Author_Institution
Information Trust Institute, University of Illinois at Urbana Champaign, Urbana, IL-USA
fYear
2015
Firstpage
617
Lastpage
622
Abstract
Malware can spread uncontrollably if left unchecked and can cause significant damage to the Advanced Metering Infrastructure (AMI) and ultimately to the underlying power grid. Application layer protocols used in the AMI are capable of carrying large payloads which could be potentially used to hide malware. Fortunately, application layer traffic in the AMI is not expected to contain executable content and hence the problem of malware detection in data payloads simply changes to the problem of executable content detection. In this paper, we propose a policy engine implementation which sits between the network and application layers and performs comprehensive syntactic and semantic rule checks on each received packet and for the presence of encryption, ARM or x86 executable content. The policy engine is integrated with the C12.22 protocol library and is primarily targeted for deployment in head end systems.
Keywords
"Malware","Data transfer","Protocols","Smart grids","Payloads","Engines","Software"
Publisher
ieee
Conference_Titel
Smart Grid Communications (SmartGridComm), 2015 IEEE International Conference on
Type
conf
DOI
10.1109/SmartGridComm.2015.7436369
Filename
7436369
Link To Document