JVM fuzzing for JIT-induced side-channel detection
Tegan Brennan, Seemanta Saha, Tevfik Bultan
Abstract
Timing side channels arise in software when a program's execution time can be correlated with security-sensitive program input. Recent results on software side-channel detection focus on analysis of program's source code. However, runtime behavior, in particular optimizations introduced during just-in-time (JIT) compilation, can impact or even introduce timing side channels in programs. In this paper, we present a technique for automatically detecting such JIT-induced timing side channels in Java programs. We first introduce patterns to detect partitions of secret input potentially separable by side channels. Then we present an automated approach for exploring behaviors of the Java Virtual Machine (JVM) to identify states where timing channels separating these partitions arise. We evaluate our technique on three datasets used in recent work on side-channel detection. We find that many code variants labeled "safe" with respect to side-channel vulnerabilities are in fact vulnerable to JIT-induced timing side channels. Our results directly contradict the conclusions of four separate state-of-the-art program analysis tools for side-channel detection and demonstrate that JIT-induced side channels are prevalent and can be detected automatically.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 35652755-b6c3-44da-91c5-8d73b7728254Cited by top-tier papers13
- QDiff: Differential Testing of Quantum Software StacksJiyuan Wang, Qian Zhang, Guoqing Harry Xu, Miryung KimASE 2021 · 48 citations
- Validating JIT Compilers via Compilation Space ExplorationCong Li, Yanyan Jiang, Chang Xu, Zhendong SuSOSP 2023 · 22 citations
- Compiler Testing using Template Java ProgramsZhiqiang Zang, Nathan Wiatrek, Milos Gligoric, August ShiASE 2022 · 21 citations
- Detecting JVM JIT Compiler Bugs via Exploring Two-Dimensional Input SpacesHaoxiang Jia, Ming Wen, Zifan Xie, Xiaochen Guo et al.ICSE 2023 · 21 citations
- DeJITLeak: eliminating JIT-induced timing side-channel leaksQi Qin, JulianAndres JiYang, Fu Song, Taolue Chen et al.FSE 2022 · 18 citations
Builds on6
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim et al.USENIX Security 2017 · 536 citations
- STACCO: Differentially Analyzing Side-Channel Traces for Detecting SSL/TLS Vulnerabilities in Secure EnclavesYuan Xiao, Mengyuan Li, Sanchuan Chen, Yinqian ZhangCCS 2017 · 77 citations
- Precise Detection of Side-Channel Vulnerabilities using Quantitative Cartesian Hoare LogicJia Chen, Yu Feng, Isil DilligCCS 2017 · 74 citations
- JIT Leaks: Inducing Timing Side Channels through Just-In-Time CompilationTegan Brennan, Nicolás Rosner, Tevfik BultanS&P 2020 · 26 citations
Related papers
- Data-Driven Debugging for Functional Side ChannelsSaeid Tizpaz-Niari, Pavol Cerný, Ashutosh TrivediNDSS 2020
- Microwalk-CI: Practical Side-Channel Analysis for JavaScript ApplicationsJan Wichelmann, Florian Sieck, Anna Pätschke, Thomas EisenbarthCCS 2022 · 12 citations
- WaSCR: A WebAssembly Instruction-Timing Side Channel RepairerLiyan Huang, Junzhou He, Chao Wang, Weihang WangWWW 2025 · 3 citations
- SCAGuard: Detection and Classification of Cache Side-Channel Attacks via Attack Behavior Modeling and Similarity ComparisonLimin Wang, Lei Bu, Fu SongDAC 2023 · 6 citations
- It's About Time: Detecting Timing Side-Channel Vulnerabilities in High-Level Synthesis DesignsDenis Zuppiger, Katharina Ceesay-Seitz, Jiahui Xu, Lana Josipović et al.CCS 2026
