节点文献

基于符号执行的软件缓存侧信道脆弱性检测技术

Cache-Based Side-Channel Vulnerability Detection Based on Symbolic Execution

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 杨超郭云飞扈红超刘文彦霍树民王亚文

【Author】 YANG Chao;GUO Yun-fei;HU Hong-chao;LIU Wen-yan;HUO Shu-min;WANG Ya-wen;National Digital Switching System Engineering & Technological Research Center;

【通讯作者】 杨超;

【机构】 国家数字交换系统工程技术研究中心

【摘要】 缓存侧信道攻击的基础是程序针对不同敏感信息将访问不同的缓存地址.本文提出基于符号执行的缓存侧信道脆弱性检测技术,通过符号化敏感信息的数据传播过程定位潜在的脆弱点,并通过比较其可能的不同缓存访问地址,判断上述代码在缓存攻击中的可利用性.本文开发了原型系统CSCVulDiscover,并针对RSA等3种密码算法的12类实现代码进行测试,总共发现了125个脆弱点.

【Abstract】 The root cause of cache-based side-channel attacks is that the application will access different cache memory depending on different values of sensitive information.This paper proposes a symbolic-execution-based vulnerability detection technology to identify the code in an application that can be exploited in cache attacks.It analyzes program’s data propagation of symbolized sensitive information to locate candidate vulnerabilities,and determines the exploitability through comparison of different possible accessed cache addresses.A prototype system called CSCVulDiscover is developed and tested against 12 kinds of implementation of 3 popular cryptographic algorithms including RSA,and the result shows that 125 vulnerabilities are detected.

【基金】 国家自然科学基金创新群体项目(No.61521003);国家自然科学基金项目(No.61602509);国家重点研发计划项目(No.2016YFB0800100,No.2016YFB0800101);河南省科技攻关计划项目(No.172102210615)
  • 【文献出处】 电子学报 ,Acta Electronica Sinica , 编辑部邮箱 ,2019年06期
  • 【分类号】TP309
  • 【被引频次】7
  • 【下载频次】143
节点文献中: 

本文链接的文献网络图示:

本文的引文网络