arXiv:2608.11802cs.CRcs.AI2026-08

软硬协同控制流监控提升攻击检测与识别精度

Towards Model-based Run-time Cybersecurity: On Control-Flow Anomaly Detection, Attack Identification, and Hardware Monitoring

论文配图:Towards Model-based Run-time Cybersecurity: On Control-Flow Anomaly Detection, Attack Identification, and Hardware Monitoring
图 1 · 摘自论文原文
  • 软件与硬件双层控制流监测,防攻击伪装
  • 硬件监控发现真实注入攻击,诊断准确率提升
  • 适合安全敏感系统如认证服务的实时防护

提升系统对网络攻击的韧性日益重要。控制流监控为运行时完整性保障和异常检测提供了理论基础。一旦检测到异常,可借助攻击树识别可能的攻击类型。然而,该方法易受伪装攻击影响,攻击者可通过操纵可观测控制流来规避检测与正确识别。本文提出一种基于模型的方法,通过结合软件与硬件层面的监控架构,增强入侵检测与攻击识别的鲁棒性。软件层观测可疑行为,硬件层独立、细致地验证这些行为,使攻击难以伪装。以认证服务为例,软件层观察到看似无害的控制流偏差,并误判为低危配置问题;而硬件层独立监控实际跳转序列后,将诊断结果修正为高置信度的代码注入或控制流劫持。该方法显著提升了异常检测能力与攻击树诊断精度。

原文摘要 · Abstract (English)

Methods to increase the resilience of systems to cyber-attacks become increasingly important. Control-flow monitoring provides a principled basis to ensure integrity and detect possible anomalies at run-time. Once anomalies have been detected, so-called attack trees can be used to identify possible types of attacks. However, this approach is vulnerable to camouflage, by which attackers try to evade detection (and correct identification) by deliberately manipulating also the system's observed control flow. In this paper, we outline a model-based approach that provides more robust intrusion detection and attack identification through an architecture that combines software- with hardware-based monitoring. In this approach, software-level observation indicates suspicious activities, while hardware-level monitoring checks them separately in more detail, making it much harder for attacks to camouflage themselves and go undetected. We illustrate the approach with an authentication-service example that captures a realistic failure mode: a software-level observer sees an anomalous but apparently harmless control-flow deviation, maps it to a benign root cause in an attack tree, but misses the true intrusion. A second, independent hardware control-flow monitor observes the actual transition sequence and thereby changes the attack-tree diagnosis from a low-severity configuration or maintenance issue to a high-confidence code-injection or control-flow hijack. In this scenario, the proposed combination of control-flow anomaly detection, attack-tree based intrusion identification, and hardware-based monitoring can improve not only anomaly detection, but also the diagnostic precision of attack-tree-based cyber-attack identification.

控制流监控入侵检测软硬协同攻击识别

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。