Sok: The challenges, pitfalls, and perils of using hardware performance counters for security

S Das, J Werner, M Antonakakis… - … IEEE Symposium on …, 2019 - ieeexplore.ieee.org
Hardware Performance Counters (HPCs) have been available in processors for more than a
decade. These counters can be used to monitor and measure events that occur at the CPU …

Hardware performance counters can detect malware: Myth or fact?

B Zhou, A Gupta, R Jahanshahi, M Egele… - Proceedings of the 2018 …, 2018 - dl.acm.org
The ever-increasing prevalence of malware has led to the explorations of various detection
mechanisms. Several recent works propose to use Hardware Performance Counters (HPCs) …

A theoretical study of hardware performance counters-based malware detection

K Basu, P Krishnamurthy, F Khorrami… - IEEE Transactions on …, 2019 - ieeexplore.ieee.org
Malware can range from simple adware to stealthy kernel control-flow modifying rootkits.
Although anti-virus software is popular, an ongoing cat-and-mouse cycle of anti-virus …

2smart: A two-stage machine learning-based approach for run-time specialized hardware-assisted malware detection

H Sayadi, HM Makrani, SMP Dinakarrao… - … , Automation & Test …, 2019 - ieeexplore.ieee.org
Hardware-assisted Malware Detection (HMD) has emerged as a promising solution to
improve the security of computer systems using Hardware Performance Counters (HPCs) …

Can hardware performance counters be trusted?

VM Weaver, SA McKee - 2008 IEEE International Symposium …, 2008 - ieeexplore.ieee.org
When creating architectural tools, it is essential to know whether the generated results make
sense. Comparing a toolpsilas outputs against hardware performance counters on an actual …

On the feasibility of online malware detection with performance counters

J Demme, M Maycock, J Schmitz, A Tang… - ACM SIGARCH …, 2013 - dl.acm.org
The proliferation of computers in any domain is followed by the proliferation of malware in
that domain. Systems, including the latest mobile platforms, are laden with viruses, rootkits …

RHMD: Evasion-resilient hardware malware detectors

KN Khasawneh, N Abu-Ghazaleh… - Proceedings of the 50th …, 2017 - dl.acm.org
Hardware Malware Detectors (HMDs) have recently been proposed as a defense against
the proliferation of malware. These detectors use low-level features, that can be collected by …

Analyzing hardware based malware detectors

N Patel, A Sasan, H Homayoun - Proceedings of the 54th Annual Design …, 2017 - dl.acm.org
Detection of malicious software at the hardware level is emerging as an effective solution to
increasing security threats. Hardware based detectors rely on Machine Learning (ML) …

Detecting malicious attacks exploiting hardware vulnerabilities using performance counters

C Li, JL Gaudiot - 2019 IEEE 43rd Annual Computer Software …, 2019 - ieeexplore.ieee.org
Over the past decades, the major objectives of computer design have been to improve
performance and to reduce cost, energy consumption, and size, while security has remained …

Non-determinism and overcount on modern hardware performance counter implementations

VM Weaver, D Terpstra, S Moore - 2013 IEEE International …, 2013 - ieeexplore.ieee.org
Ideal hardware performance counters provide exact deterministic results. Real-world
performance monitoring unit (PMU) implementations do not always live up to this ideal …