{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:49:44Z","timestamp":1750308584676,"version":"3.41.0"},"reference-count":38,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2017,12,7]],"date-time":"2017-12-07T00:00:00Z","timestamp":1512604800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1615890"],"award-info":[{"award-number":["CNS-1615890"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2018,3,31]]},"abstract":"<jats:p>Network-connected embedded systems grow on a large scale as a critical part of Internet of Things, and these systems are under the risk of increasing malware. Anomaly-based detection methods can detect malware in embedded systems effectively and provide the advantage of detecting zero-day exploits relative to signature-based detection methods, but existing approaches incur significant performance overheads and are susceptible to mimicry attacks. In this article, we present a formal runtime security model that defines the normal system behavior including execution sequence and execution timing. The anomaly detection method in this article utilizes on-chip hardware to non-intrusively monitor system execution through trace port of the processor and detect malicious activity at runtime. We further analyze the properties of the timing distribution for control flow events, and select subset of monitoring targets by three selection metrics to meet hardware constraint. The designed detection method is evaluated by a network-connected pacemaker benchmark prototyped in FPGA and simulated in SystemC, with several mimicry attacks implemented at different levels. The resulting detection rate and false positive rate considering constraints on the number of monitored events supported in the on-chip hardware demonstrate good performance of our approach.<\/jats:p>","DOI":"10.1145\/3122785","type":"journal-article","created":{"date-parts":[[2017,12,11]],"date-time":"2017-12-11T13:26:47Z","timestamp":1512998807000},"page":"1-27","update-policy":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["Time and Sequence Integrated Runtime Anomaly Detection for Embedded Systems"],"prefix":"10.1145","volume":"17","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-6514-4844","authenticated-orcid":false,"given":"Sixing","family":"Lu","sequence":"first","affiliation":[{"name":"University of Arizona, Tucson, AZ"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Roman","family":"Lysecky","sequence":"additional","affiliation":[{"name":"University of Arizona, Tucson, AZ"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2017,12,7]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"ARM. 2011. Embedded Trace Macrocell ETMv1.0 to ETMv3.5 Architecture Specification. ARM. 2011. Embedded Trace Macrocell ETMv1.0 to ETMv3.5 Architecture Specification."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/DATE.2005.266"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1176254.1176281"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.12"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1814217.1814218"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1214\/10-AOS799"},{"volume-title":"USENIX Security Symposium, (July","year":"2005","author":"Chen S.","key":"e_1_2_1_7_1"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2010.17"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45848-4_57"},{"volume-title":"ATM and Card Authorization Systems. https:\/\/2.zoppoz.workers.dev:443\/https\/www.ffiec.gov","year":"2014","author":"Federal Financial Institutions Examination Council (FFEIC).","key":"e_1_2_1_10_1"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-02918-9_13"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030126"},{"volume-title":"Technical Report","year":"2007","author":"Idika N.","key":"e_1_2_1_13_1"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-28756-5_14"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2656075.2656092"},{"volume-title":"Asia South Pacific Design Automation Conference (Jan.","year":"2015","author":"Lu S.","key":"e_1_2_1_16_1"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2818362.2818365"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2010.32"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2857705.2857746"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/12.980003"},{"volume-title":"Threats Report","year":"2015","author":"Labs McAfee","key":"e_1_2_1_21_1"},{"volume-title":"Washington Tech. Rep, (Oct.","year":"2014","author":"McCarthy C.","key":"e_1_2_1_22_1"},{"key":"e_1_2_1_23_1","unstructured":"MicroBlaze. 2009. Microblaze processor reference guide embedded development kit EDK 11.4. 102--104. MicroBlaze. 2009. Microblaze processor reference guide embedded development kit EDK 11.4. 102--104."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/2442116.2442135"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1391469.1391686"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/TVLSI.2010.2053856"},{"key":"e_1_2_1_27_1","doi-asserted-by":"crossref","unstructured":"M. Prates V. H. Lachos and C. R. B. Cabral. 2011. mixsmsn: Fitting finite mixture of scale mixture of skew normal distributions. R package version 0. 2-9 M. Prates V. H. Lachos and C. R. B. Cabral. 2011. mixsmsn: Fitting finite mixture of scale mixture of skew normal distributions. R package version 0. 2-9","DOI":"10.32614\/CRAN.package.mixsmsn"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/LES.2012.2218630"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2010.64"},{"key":"e_1_2_1_30_1","first-page":"21","article-title":"Understanding precision in host based intrusion detection","volume":"4637","author":"Sharif M. I.","year":"2007","journal-title":"International Symposium on Research in Attacks, Intrusions and Defenses."},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2388936.2388948"},{"volume-title":"https:\/\/2.zoppoz.workers.dev:443\/http\/Ha.ckers.org\/slowloris\/","year":"2014","author":"Slowloris HTTP","key":"e_1_2_1_32_1"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.5555\/1965602"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586145"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2744769.2744869"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/RTAS.2013.6531076"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1086297.1086305"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/1795194.1795210"}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3122785","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3122785","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3122785","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T19:05:08Z","timestamp":1750273508000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3122785"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,12,7]]},"references-count":38,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2018,3,31]]}},"alternative-id":["10.1145\/3122785"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3122785","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"type":"print","value":"1539-9087"},{"type":"electronic","value":"1558-3465"}],"subject":[],"published":{"date-parts":[[2017,12,7]]},"assertion":[{"value":"2016-11-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2017-07-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2017-12-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}