Sonar: A Hardware Fuzzing Framework to Uncover Contention Side Channels in Processors
Kanqi Zhang, Peinan Li, Miao Li, Xin Tian, Zelong Du, Quanchen Liu, Yongqiang Lyu, Yu Jiang, Dan Meng, Rui Hou
Abstract
Contention-based side channels, rooted in resource sharing, have emerged as a significant security threat in modern processors.These side channels allow attackers to leverage timing differences caused by conflicts in execution ports, caches, or interconnects to infer secret information such as cryptographic keys or enclave-resident data.Despite increasing awareness, detecting such channels remains challenging because triggering contentions requires precisely orchestrating specific microarchitectural states, which is often difficult in practice, especially for timing-sensitive contentions.This paper introduces Sonar, the first systematic and automated fuzzing framework designed to uncover contention side channels in processors.Our core idea is to leverage microarchitectural states to guide testcase generation, enabling the precise triggering of microarchitectural events with stringent conditions.Sonar is built on the key observation that multiplexers (MUXes) are hotspots for contention, as resource contention frequently involves data routing and signal selection, which are fundamentally implemented
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get a10ae520-f568-496e-8ef1-e5b96ea07bc6Related papers
- PortRush: Detect Write Port Contention Side-Channel Vulnerabilities via Hardware FuzzingPeihong Lin, Pengfei Wang, Lei Zhou, Gen Zhang et al.NDSS 2026
- ExfilState: Automated Discovery of Timer-Free Cache Side Channels on ARM CPUsFabian Thomas, Michael Torres, Daniel Moghimi, Michael SchwarzCCS 2025
- Osiris: Automated Discovery of Microarchitectural Side ChannelsDaniel Weber, Ahmad Ibrahim, Hamed Nemati, Michael Schwarz et al.USENIX Security 2021 · 75 citations
- Lord of the Ring(s): Side Channel Attacks on the CPU On-Chip Ring Interconnect Are PracticalRiccardo Paccagnella, Licheng Luo, Christopher W. FletcherUSENIX Security 2021 · 121 citations
- HARTBREAKER: Deterministic Fuzzing of Multi-Hart RISC-V CPUs with Non-Deterministic ProgramsQuentin Bordier, Tobias Kovats, Flavien Solt, Kaveh RazaviISCA 2026
