Smart-Guard: Defending User Input from Malware
- Michael Denzel,
- ,
- Mark Ryan
- University of Birmingham,
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-reviewPublication Information
Output type
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-reviewOriginal language
EnglishPages from-to (Number of pages)
Pages 502-509 (8 pages)Publication milestones
- Published - 08/08/2016
Publication status
Published - 08/08/2016
Publisher
IEEE, United StatesISBN (Print)
978-1-5090-2770-5Publication IDs
- Scopus: 85013156185
Host publication title
2016 Intl IEEE Conferences on Ubiquitous Intelligence & Computing, Advanced and Trusted Computing, Scalable Computing and Communications, Cloud and Big Data Computing, Internet of People, and Smart World Congress (UIC/ATC/ScalCom/CBDCom/IoP/SmartWorld)Abstract
Trusted input techniques can profoundly enhance
a variety of scenarios like online banking, electronic voting,
Virtual Private Networks, and even commands to a server
or Industrial Control System. To protect the system from
malware of the sender’s computer, input needs to be reliably
authenticated. Previous research in this field is based on fixed
assumptions about trustworthy components and is, thus, too
rigid for this use case.
We present Smart-Guard, a method to protect user input
into a system even if the attacker controls – to us unknown –
parts of the underlying system. Our approach ensures integrity
of user input even when up to two of three devices are
compromised; confidentiality holds for one malicious device.
In this way, Smart-Guard has flexible trust assumptions, and
does not require any particular part of the system to be trusted.
To prove our claims, we formally verified our protocol using
the state-of-the-art protocol verifier ProVerif. Additionally, we
define a new class of techniques, malware tolerance, which operate
securely even when the system is infected with malware.
a variety of scenarios like online banking, electronic voting,
Virtual Private Networks, and even commands to a server
or Industrial Control System. To protect the system from
malware of the sender’s computer, input needs to be reliably
authenticated. Previous research in this field is based on fixed
assumptions about trustworthy components and is, thus, too
rigid for this use case.
We present Smart-Guard, a method to protect user input
into a system even if the attacker controls – to us unknown –
parts of the underlying system. Our approach ensures integrity
of user input even when up to two of three devices are
compromised; confidentiality holds for one malicious device.
In this way, Smart-Guard has flexible trust assumptions, and
does not require any particular part of the system to be trusted.
To prove our claims, we formally verified our protocol using
the state-of-the-art protocol verifier ProVerif. Additionally, we
define a new class of techniques, malware tolerance, which operate
securely even when the system is infected with malware.
Publication metrics
PlumX, opens in new tab
Captures
9
Citations
2
Access to documents
Related Event
Title
The 13th IEEE International Conference on Advanced and Trusted Computing: ATC 2016
Event type
ConferenceDate
18/07/2016 - 21/07/2016Location
University Paul Sabatier of ToulouseToulouseFrance
