Cover Image: December 2012 Scientific American Magazine See Inside

New "Symbiote" May Protect Microchips from Cyber Attack

Security experts are working to thwart a potentially devastating cyber attack















Share on Tumblr

symbiotes, cyberattack, microchips, digital jail, binary code, handcuffs

Image: Thomas Fuchs

As microchips have grown smaller and more powerful, they have infiltrated virtually every corner of society, from smartphones to medical devices to the controls that regulate rail lines, power grids and water treatment facilities. Computer security experts have been warning that these embedded computers are highly vulnerable to attack because they are increasingly networked with other computers and because they have virtually no defenses protecting their firmware, programs that are hardwired onto the chip. In October, following a wave of network attacks believed to have originated in Iran, Secretary of Defense Leon Panetta warned that a “cyber Pearl Harbor” could be imminent.

Security experts used to take firmware for granted, notes Scott Borg, director of the nonprofit Cyber Consequences Unit, because, unlike software, it was designed to operate unchanged for long periods of time. “Yet the circuits embodying these programs are designed to accept a significant number of rewrites, so they can still be altered by cyberattackers,” he says.

Engineers are making headway in protecting these chips. One new approach, described at a computer security conference in July, is a program that would scan random chunks of firmware code to check for signs of intrusion. Developers Ang Cui and Sal Stolfo of Columbia University say their “symbiote” can work with any type of firmware without slowing a computer's processing speed. It may also detect malware that no one had any way of noticing before, potentially shedding light on an “untold chapter of the history of Internet warfare,” Cui says. They plan to deliver a prototype for U.S. government testing by the end of 2012.

Borg calls Stolfo and Cui's approach “very promising.” Marc Dacier, a senior director at Symantec Research Labs, asserts that a major obstacle to any defense measure is getting companies to adopt it. The Pentagon is pushing for legislation to require the private sector to cooperate with government on cybersecurity issues. Without such legislation, Panetta said in his October speech, “we are, and we will be, vulnerable.”



This article was originally published with the title Digital Danger.



Subscribe     Buy This Issue

Already a Digital subscriber? Sign-in Now
If your institution has site license access, enter here.

Comments

Add Comment
Leave this field empty

Add a Comment

You must sign in or register as a ScientificAmerican.com member to submit a comment.
Click one of the buttons below to register using an existing Social Account.

More from Scientific American

See what we're tweeting about

Scientific American Editors

More »

Free Newsletters


Get the best from Scientific American in your inbox

Solve Innovation Challenges

Powered By: Innocentive

  SA Digital

Latest from SA Blog Network

  SA Digital

Science Jobs of the Week

Email this Article

New "Symbiote" May Protect Microchips from Cyber Attack: Scientific American Magazine

X
Scientific American Magazine

Subscribe Today

Save 66% off the cover price and get a free gift!

Learn More >>

X

Please Log In

Forgot: Password

X

Account Linking

Welcome, . Do you have an existing ScientificAmerican.com account?

Yes, please link my existing account with for quick, secure access.



Forgot Password?

No, I would like to create a new account with my profile information.

Create Account
X

Report Abuse

Are you sure?

X

Institutional Access

It has been identified that the institution you are trying to access this article from has institutional site license access to Scientific American on nature.com. To access this article in its entirety through site license access, click below.

Site license access
X

Error

X

Share this Article

X