Smart Detection of Obfuscated Thermal Covert Channel Attacks in Many-core Processors
Jeferson González-Gómez, Mohammed Bakr Sikal, Heba Khdr, Lars Bauer, Jörg Henkel
Abstract
In thermal covert channel (TCC) attacks, malicious applications seek to leak private information in a stealthy and hard-to-detect manner. State-of-the-art approaches for TCC detection employ the Discrete Fourier Transform (DFT) combined with heuristics to identify possible channels. However, as we demonstrate in this paper, these approaches are limited when detecting short-duration attacks, where an attacker intentionally halts the transmission for a time interval to avoid the detection. In order to overcome this limitation of the state-of-the-art solutions, we propose the first detection method for short-duration TCC attacks. Our solution, Dotecca, is a machine learning-based technique that employs short windows of time-domain measurements instead of the DFT to detect TCCs. To evaluate our solution, we introduce a new obfuscated short-duration attack that disguises as a regular application from the perspective of a DFT spectrum. Our experiments show that the new obfuscated attack is able to remain undetected even under advanced DFT-based state-of-the-art detection approaches, reducing their detection accuracy to about 18 %. In contrast, our smart detection approach is able to detect state-of-the-art and new obfuscated attacks with an accuracy of 99 %. Moreover, our solution reduces the overhead of the DFT-based state-of-the-art solution by more than 14 ×.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- On Countermeasures Against the Thermal Covert Channel Attacks Targeting Many-core SystemsHengli Huang, Xiaohang Wang, Yingtao Jiang, Amit Kumar Singh et al.DAC 2020 · 20 citations
- ICARUS: Learning on IQ and Cycle Frequencies for Detecting Anomalous RF Underlay SignalsDebashri Roy, Vini Chaudhury, Chinenye Tassie, Chad M. Spooner et al.INFOCOM 2023 · 16 citations
- ThermalScope: A Practical Interrupt Side Channel Attack Based on Thermal Event InterruptsXin Zhang, Zhi Zhang, Qingni Shen, Wenhao Wang et al.DAC 2024 · 12 citations
- Realtime Robust Malicious Traffic Detection via Frequency Domain AnalysisChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2021 · 194 citations
- When LoRa Meets EMR: Electromagnetic Covert Channels Can Be Super ResilientCheng Shen, Tian Liu, Jun Huang, Rui TanS&P 2021 · 50 citations
