Validation of Abstract Side-Channel Models for Computer Architectures
Hamed Nemati, Pablo Buiras, Andreas Lindner, Roberto Guanciale, Swen Jacobs
Abstract
Observational models make tractable the analysis of information flow properties by providing an abstraction of side channels. We introduce a methodology and a tool, Scam-V, to validate observational models for modern computer architectures. We combine symbolic execution, relational analysis, and different program generation techniques to generate experiments and validate the models. An experiment consists of a randomly generated program together with two inputs that are observationally equivalent according to the model under the test. Validation is done by checking indistinguishability of the two inputs on real hardware by executing the program and analyzing the side channel. We have evaluated our framework by validating models that abstract the data-cache side channel of a Raspberry Pi 3 board with a processor implementing the ARMv8-A architecture. Our results show that Scam-V can identify bugs in the implementation of the models and generate test programs which invalidate the models due to hidden microarchitectural behavior.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ffcb87de-b5f3-411e-961f-d91e55e7c383Cited by top-tier papers15
- Revizor: testing black-box CPUs against speculation contractsOleksii Oleksenko, Christof Fetzer, Boris Köpf, Mark SilbersteinASPLOS 2022 · 36 citations
- Specification and Verification of Side-channel Security for Open-source Processors via Leakage ContractsZilong Wang, Gideon Mohr, Klaus von Gleissenthall, Jan Reineke et al.CCS 2023 · 20 citations
- Serberus: Protecting Cryptographic Code from Spectres at Compile-TimeNicholas Mosier, Hamed Nemati, John C. Mitchell, Caroline TrippelS&P 2024 · 16 citations
- Testing Side-channel Security of Cryptographic Implementations against Future MicroarchitecturesGilles Barthe, Marcel Böhme, Sunjay Cauligi, Chitchanok Chuengsatiansup et al.CCS 2024 · 6 citations
- Microarchitectural Leakage Templates and Their Application to Cache-Based Side ChannelsAhmad Ibrahim, Hamed Nemati, Till Schlüter, Nils Ole Tippenhauer et al.CCS 2022 · 4 citations
Builds on4
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Verifying Constant-Time ImplementationsJosé Bacelar Almeida, Manuel Barbosa, Gilles Barthe, François Dupressoir et al.USENIX Security 2016 · 274 citations
- Cache Storage Channels: Alias-Driven Attacks and Verified CountermeasuresRoberto Guanciale, Hamed Nemati, Christoph Baumann, Mads DamS&P 2016 · 103 citations
- Malicious Management Unit: Why Stopping Cache Attacks in Software is Harder Than You ThinkStephan van Schaik, Cristiano Giuffrida, Herbert Bos, Kaveh RazaviUSENIX Security 2018 · 64 citations
Related papers
- Validation of Side-Channel Models via Observation RefinementPablo Buiras, Hamed Nemati, Andreas Lindner, Roberto GuancialeMICRO 2021 · 18 citations
- SpecuSym: speculative symbolic execution for cache timing leak detectionShengjian Guo, Yueqi Chen, Peng Li, Yueqiang Cheng et al.ICSE 2020 · 34 citations
- CaSym: Cache Aware Symbolic Execution for Side Channel Detection and MitigationRobert Brotzman, Shen Liu, Danfeng Zhang, Gang Tan et al.S&P 2019 · 77 citations
- Architectural Mimicry: Innovative Instructions to Efficiently Address Control-Flow Leakage in Data-Oblivious ProgramsHans Winderix, Marton Bognar, Job Noorman, Lesly-Ann Daniel et al.S&P 2024 · 5 citations
- Exposing cache timing side-channel leaks through out-of-order symbolic executionShengjian Guo, Yueqi Chen, Jiyong Yu, Meng Wu et al.OOPSLA 2020 · 7 citations
