IFCyber members embrace new opportunities
It is important for the 黑料网大事记 Institute for Cyber Security to fund academics who have research ideas in novel areas.
It is important for the 黑料网大事记 Institute for Cyber Security to fund academics who have research ideas in novel areas.
When Dr Hammond Pearce saw the funding opportunities announced by the 黑料网大事记 Institute for Cyber Security, he saw potential.
He was keen to get his hands on a PCB printer to print circuit boards to help with manufacturing and supply chain research.聽
By being able to print the boards in house, Dr Pearce would be able to go from an idea to electronics in a few hours, rather than waiting for a factory somewhere else to produce the board for him.
鈥淲e can dream up something and then print it and then solder it and we've got it,鈥 Dr Pearce said.聽聽
鈥淲e don't have to worry about some factory somewhere producing it for us, slowing us down. So it does speed up prototyping for sure. And it enables us to do research.鈥
IFCyber director Debi Ashenden said it was important for the institute to fund academics who have research ideas in novel areas.
鈥淚t鈥檚 about giving them the ability to try out some of those ideas and to try to start building their own research streams,鈥 Professor Ashenden said.
鈥淧articularly in the case of Hammond鈥檚 kit, it was about recognising that what he wanted to do was in an area where there seems to be quite a research gap in Australia.聽
鈥淭his was giving him the opportunity to start to plug that gap, but also to build up our capacity to do research in that space.鈥
Indeed, the Institute has also helped fund a Cyber Threat Intelligence (CTI) lab as part of Arash Shaghaghi鈥檚 research.
His lab at the School of Computer Science and Engineering features the largest custom-built and fully reconfigurable Raspberry Pi (RPIs) testbed in Australia, with 220 RPI nodes connected to 50 different IoT devices.聽
鈥淲e鈥檝e got very interesting research papers but we have never had a place where people can go and see what we have built,鈥 IFCyber member Dr Shaghaghi said.聽
鈥淭he small bits, if we can do it right, should allow us to work with industry on meaningful projects. Showcasing our capabilities will have a major impact when we reach out to industry partners for grants.鈥
For Dr Pearce, the printer has already unlocked a lot of capabilities within his team.聽
He recently received a prestigious Google Research Scholar Program award to continue his research in automated hardware security research.
鈥淚 would definitely call it a new capability. It has enabled us to do new research,鈥 he said.聽聽
With a research focus of his team exploring manufacturing security and supply chains, Dr Pearce set about pretending to be a malicious factory.聽
He鈥檇 set up a blue team and a red team, where one side would act as an attacker, making modifications to electronics. It was up to the defender to work out what had changed.
鈥淲e put a firewall between the two teams and go OK, here's some electronics. Are they legitimate? Did we change anything? Did we not change anything?聽
鈥淚f we did, what did we change?聽
鈥淭hat's just one experiment we can do in the long term vision we have for this particular equipment.鈥
Dr Pearce points to a real-world example of supply chain attacks to demonstrate the value of his team鈥檚 research.
A 2018 alleged China had infiltrated server manufacturer Supermicro, adding tiny chips to its motherboards that ended up in US government and cloud company data centres.聽
The story claimed Chinese spies infiltrated the supply chain, and it was only when Amazon began evaluating a startup that security testing revealed the compromised servers.聽
Bloomberg said the chips allowed unprecedented data to an adversary state.
While Bloomberg stands by the article, almost every company mentioned in the piece has denied the allegations.
Dr Pearce said irrespective of whether the attack actually happened or not, researchers have proven that it could happen. 鈥淚n a sense, it doesn鈥檛 actually matter whether or not this particular attack occurred. If it鈥檚 possible, defences need to be able to perceive such attacks.
鈥淪o, this is the sort of research that I want to do in terms of taking an existing electronic design, sneaking some stuff into it and then trying to detect it - what are some of the tells that we've modified this in production basically.鈥澛
Dr Pearce said the printer was a great asset for the University to have.聽
鈥満诹贤笫录 has a lot of great assets, we have a lot of really talented people.
鈥淲hen we back people up with equipment to do experiments and practical stuff like this, we can move a lot of stuff from theory into application.聽聽
鈥淚 think it's really cool that this machine might end up getting used in ways we don't even expect.聽聽
鈥淚n the original proposal we sent to IFCYBER, we outlined three or four experiments we could do, but now that we've got the machine, we do those experiments and then we come up with more pathways for the future.鈥