An NDSU team takes on the hidden dangers lurking in modern microchips

Kushal Ponugoti, left, and JohnPaul Asuai

Kushal Ponugoti, left, and JohnPaul Asuai, right, want their research to help microchip designers protect technology against attacks. Photo by NDAREC/Liza Kessel

Kushal Ponugoti, left, and JohnPaul Asuai

Kushal Ponugoti quoteAnyone who grew up watching “Tom and Jerry” understands the basics of a cat-and-mouse game. The cat devises a new scheme. The mouse finds a way around it. Then the chase begins again.

Beneath the entertainment and slapstick was a lesson in strategy. We see it today in the world of computer security. Every new trap by bad actors inspires a clever escape by computer engineers. And like the endless rivalry between Tom and Jerry, this contest is unlikely to have a final winner.

Only now, the stakes are far higher than a cartoon chase. A successful exploit could put sensitive data and critical communications at risk.

Researchers from North Dakota State University (NDSU) entered the battle over cybersecurity about two-and-a-half years ago, when graduate researcher Kushal Ponugoti was working on his Ph.D. in electrical and computer engineering. This spring, he and his team published the results of that work, which would expose yet another security threat and a solution to patch it.

Threat neutralized. For now, at least.

More importantly, however, their study proved it’s not only software and networks that need protection, but also hardware. With the findings published online, the researchers are urging chip designers and hardware security engineers to strengthen their defenses.
 

PROTECT YOURSELF FROM SECURITY THREATS

•    Buy technology from well-established players in the marketplace. Avoid counterfeit or tampered devices. Choose established companies that provide regular security updates and have transparent practices.
•    Keep devices updated. Software bugs are much easier to fix than hardware bugs. Constantly updating your operating system or application defends against newly discovered security vulnerabilities. Enable automatic updates to stay on top of it without having to remember.
•    Use strong, unique passwords. Reusing passwords across accounts allows a single breach to expose multiple services. Enabling multi-factor authentication also helps protect you against the risk of a compromised account.
•    Secure your home network. Use a strong Wi-Fi password, change default router credentials and keep router firmware updated. Remove unsupported devices which are no longer receiving software updates to patch vulnerabilities.

THE CAT SETS A TRAP
Attackers all over the globe are attempting to trap or outsmart military systems, major industries and even the average consumer by hiding components within computer hardware. They’re smart, sophisticated and ever evolving.

The cat, in this scenario, has learned the element of surprise. An attacker, for example, may even insert Trojan hardware that can stay quiet and undetected in a computer chip used for months before ever launching its attack.

In 2008, an article titled “The Hunt for the Kill Switch” exposed the vulnerability of military hardware to attackers. The paper raised the concern that even the U.S. Department of Defense could be using microtechnology containing a hidden “kill switch” that would allow a bad actor to disable that chip. The implications meant military equipment or national defense systems could go down at the hands of attackers.

“Ever since then, there have been vulnerabilities showing up left, right and center. And unfortunately, there is no one fix to it,” says Ponugoti, now an assistant professor at NDSU’s College of Engineering.
 

THE MOUSE ESCAPES AGAIN
Researchers have been hard at work around the globe for nearly two decades to dodge these attacks by identifying vulnerabilities faster. As technology and the world have evolved, the system has become far more complicated, with constant attacks moving at a rapid pace.

Ponugoti, along with his NDSU graduate student Chukwunalu (JohnPaul) Asuai and two researchers from Southern Illinois University Edwardsville, studied a particular type of microchip rated for use in mission-critical conditions. You might find these computer chips in space exploration, military systems and automotive electronics, because they can function in extreme temperatures and radiation.

“They test the normal stuff,” Asuai says about companies currently building these chips. “But they leave out hidden parts of a circuit an attacker can compromise. So, our work actually went deeper than what is normal.”

By applying formal verification, a mathematical logic that would test for all possible scenarios that could activate the malicious components, their study is the first of its kind to prove these particular chips can be vulnerable.

Even better, they offered a form of protection that can save time and money.
 

THE GLOBAL SUPPLY CHAIN COMPLICATES THE GAME
Shoring up hardware security risks is complicated. Computer chips are not designed by one single company. Many organizations from around the world contribute design software, hardware components, testing tools and manufacturing services.

“While this collaborative approach has made chip development faster and more efficient, it has also created more opportunities for a malicious actor to interfere with the process,” Ponugoti says.

Discovering security threats after a chip has already been manufactured and is in use may require recalling devices, upgrading large amounts of infrastructure, and ultimately, redesigning those systems. It’s both time-consuming and expensive.

The researchers say it typically takes a year and a half to make one of these computer chips from scratch, with about 80% of that time spent on design and verification. So, their testing methods focus on the design stage, allowing designers to make changes quickly and efficiently.
 

AI INTRODUCES A THIRD PLAYER
While globalization is speeding up this cat-and-mouse game, artificial intelligence (AI) has introduced an entirely new set of complications.

Ponugoti explains it is “just another player” in the whole design and manufacturing cycle. The trouble is this player can compete for either team. Engineers and designers are using AI to spot and fix flaws faster, while attackers are using it to more skillfully disguise their traps. Even too much reliance on AI could introduce risks if an engineer isn’t careful to test and verify the code it produces, therefore introducing a false sense of security.

“In as much as AI is a solution, it is a problem, too,” Asuai explains.
 

ONTO THE NEXT BATTLE
With the study published and already reaching engineers who are working with these types of circuits, the methodologies Ponugoti and Asuai discovered are ready to be put into practice. Now, chip designers have a new tool in their arsenal to protect sensitive information and communication.

But, as we know, this game always means staying one step ahead.

“Information leaking is only one part of hardware security. There are other security threats,” Ponugoti says, setting his sights on their next challenge.

His team is already working on methodologies to detect Trojan hardware that could make a chip stop working entirely after a fixed amount of time.

Stakes high. Team ready. Game on.

___
Hope Sisk is managing editor of North Dakota Living. She can be reached at hsisk@ndarec.com.