By turning computer circuits into unsolvable puzzles, a University of Michigan team aims to create an unhackable computer with a new $3.6 million grant from the Defense Advanced Research Projects Agency.
Todd Austin, U-M professor of computer science and engineering, leads the project, called MORPHEUS. Its cybersecurity approach is dramatically different from today’s, which relies on software—specifically software patches to vulnerabilities that have already been identified. It’s been called the “patch and pray” model, and it’s not ideal.
This spring, DARPA announced a $50 million program in search of cybersecurity solutions that would be baked into hardware.
“Instead of relying on software Band-Aids to hardware-based security issues, we are aiming to remove those hardware vulnerabilities in ways that will disarm a large proportion of today’s software attacks,” said Linton Salmon, manager of DARPA’s System Security Integrated Through Hardware and Firmware program.
The U-M grant is one of nine that DARPA has recently funded through SSITH.
MORPHEUS outlines a new way to design hardware so that information is rapidly and randomly moved and destroyed. The technology works to elude attackers from the critical information they need to construct a successful attack. It could protect both hardware and software.
“We are making the computer an unsolvable puzzle,” Austin said. “It’s like if you’re solving a Rubik’s Cube and every time you blink, I rearrange it.”
In this way, MORPHEUS could protect against future threats that have yet to be identified, a dreaded vulnerability that the security industry called a “zero day exploit.”
“What’s incredibly exciting about the project is that it will fix tomorrow’s vulnerabilities,” Austin said. “I’ve never known any security system that could be future proof.”
Austin said his approach could have protected against the Heartbleed bug discovered in 2014. Heartbleed allowed attackers to read the passwords and other critical information on machines.
“Typically, the location of this data never changes, so once attackers solve the puzzle of where the bug is and where to find the data, it’s ‘game over,'” Austin said.
Under MORPHEUS, the location of the bug would constantly change and the location of the passwords would change, he said. And even if an attacker were quick enough to locate the data, secondary defenses in the form of encryption and domain enforcement would throw up additional roadblocks. The bug would still be there, but it wouldn’t matter. The attacker won’t have the time or the resources to exploit it.
“These protections don’t exist today because they are too expensive to implement in software, but with DARPA’s support we can take the offensive against attackers with new defenses in hardware and implement then with virtually no impact to software,” Austin said.
More than 40 percent of the “software doors” that hackers have available to them today would be closed if researchers could eliminate seven classes of hardware weaknesses, according to DARPA. The hardware weakness classes have been identified by a crowd-source listing of security vulnerabilities called the Common Weakness Enumeration. The classes are: permissions and privileges, buffer errors, resource management, information leakage, numeric errors, crypto errors, and code injection.
DARPA is aiming to render these attacks impossible within five years. If developed, MORPHEUS could do it now, Austin said.
While the complexity required might sound expensive, Austin said he’s confident his team can make it possible at low cost.
The Latest on: Unhackable computer
- C64 minion May 5, 2020 at 5:00 pm
In our continuing series of, ‘point and laugh at this guy’, I present a Kickstarter for the, “World’s First Patented Unhackable Computer ... The C64 Mini is a pocket-sized Linux device ...
- What To Expect In The Emerging Age Of Quantum Computingon April 21, 2020 at 2:23 pm
Though the full effects of quantum computing likely won’t be felt for a number of years, the technology recently moved to the commercial market, and attorneys must begin to consider its vast potential ...
- Hackaday linkson April 20, 2020 at 5:00 pm
In our continuing series of, ‘point and laugh at this guy’, I present a Kickstarter for the, “World’s First Patented Unhackable Computer Ever”. It’s also a real web site and there ...
- Is it safe to leave your webcam uncovered after using video chat apps?on April 17, 2020 at 3:45 am
So, if a computer has comprehensive anti-malware ... there used to be urban legends that the Mac operating system was “unhackable”, but as the number of Mac users rose, so did the amount ...
- Toward an unhackable quantum interneton April 14, 2020 at 2:09 pm
In essence, a quantum repeater is a small, special-purpose quantum computer. At each stage of such a network, quantum repeaters must be able to catch and process quantum bits of quantum information to ...
- Toward an unhackable quantum interneton March 30, 2020 at 5:30 pm
Use your mouse to right-click (Mac users may need to Ctrl-click) the link above and choose the option that will save the file or target to your computer.
- Soldiers may 'wear' unhackable computers into combaton September 3, 2019 at 9:14 am
Vulnerability to certain individual systems could increase if all technologies were connected to a central computer network because an intruder would have wide-ranging access across a range of ...
- John McAfeeon January 14, 2019 at 1:41 pm
In 2017, John McAfee, the antivirus magnate, got a little caught up in Bitcoin’s hype cycle. When asked if Bitcoin would ... Exactly two years ago, John McAfee first announced he would eat his ...
- Resetting our password habitson August 11, 2017 at 6:45 am
A CBS News poll found that roughly one in four people has to reset a computer password at least ... goes in search of what makes passwords unhackable, and learns about new technologies that ...
- Otago researchers a step closer to developing 'unhackable' computeron January 12, 2015 at 7:55 pm
In what could be a major breakthrough, Otago University researchers say they're a step closer to developing a virtually unhackable computer. "So this is different ways where you can take light ...
via Google News and Bing News