Precise Detection of Side-Channel Vulnerabilities using Quantitative Cartesian Hoare Logic
Jia Chen, Yu Feng, Isil Dillig
Abstract
This paper presents Themis, an end-to-end static analysis tool for finding resource-usage side-channel vulnerabilities in Java applications. We introduce the notion of ϵ-bounded non-interference, a variant and relaxation of Goguen and Meseguer's well-known non-interference principle. We then present Quantitative Cartesian Hoare Logic (QCHL), a program logic for verifying ϵ-bounded noninterference. Our tool, Themis, combines automated reasoning in CHL with lightweight static taint analysis to improve scalability. We evaluate Themis on well known Java applications and demonstrate that Themis can find unknown side-channel vulnerabilities in widely-used programs. We also show that Themis can verify the absence of vulnerabilities in repaired versions of vulnerable programs and that Themis compares favorably against Blazer, a state-of-the-art static analysis tool for finding timing side channels in Java applications.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 60d94610-8d09-49fa-994a-2ba8e68b3b01Cited by top-tier papers21
- CaSym: Cache Aware Symbolic Execution for Side Channel Detection and MitigationRobert Brotzman, Shen Liu, Danfeng Zhang, Gang Tan et al.S&P 2019 · 77 citations
- "They're not that hard to mitigate": What Cryptographic Library Developers Think About Timing AttacksJan Jancar, Marcel Fourné, Daniel De Almeida Braga, Mohamed Sabt et al.S&P 2022 · 61 citations
- HyDiff: hybrid differential software analysisYannic Noller, Corina S. Pasareanu, Marcel Böhme, Youcheng Sun et al.ICSE 2020 · 37 citations
- SpecuSym: speculative symbolic execution for cache timing leak detectionShengjian Guo, Yueqi Chen, Peng Li, Yueqiang Cheng et al.ICSE 2020 · 34 citations
- JVM fuzzing for JIT-induced side-channel detectionTegan Brennan, Seemanta Saha, Tevfik BultanICSE 2020 · 26 citations
Builds on3
- Verifying Constant-Time ImplementationsJosé Bacelar Almeida, Manuel Barbosa, Gilles Barthe, François Dupressoir et al.USENIX Security 2016 · 274 citations
- Verifying and Synthesizing Constant-Resource Implementations with TypesVan Chan Ngo, Mario Dehesa-Azuara, Matthew Fredrikson, Jan HoffmannS&P 2017 · 51 citations
- Secure, Precise, and Fast Floating-Point Operations on x86 ProcessorsAshay Rane, Calvin Lin, Mohit TiwariUSENIX Security 2016 · 34 citations
Related papers
- JIT Leaks: Inducing Timing Side Channels through Just-In-Time CompilationTegan Brennan, Nicolás Rosner, Tevfik BultanS&P 2020 · 26 citations
- Data-Driven Debugging for Functional Side ChannelsSaeid Tizpaz-Niari, Pavol Cerný, Ashutosh TrivediNDSS 2020
- DeJITLeak: eliminating JIT-induced timing side-channel leaksQi Qin, JulianAndres JiYang, Fu Song, Taolue Chen et al.FSE 2022 · 18 citations
- QFuzz: quantitative fuzzing for side channelsYannic Noller, Saeid Tizpaz-NiariISSTA 2021 · 15 citations
- It's About Time: Detecting Timing Side-Channel Vulnerabilities in High-Level Synthesis DesignsDenis Zuppiger, Katharina Ceesay-Seitz, Jiahui Xu, Lana Josipović et al.CCS 2026
