SCAD: Towards a Universal and Automated Network Side-Channel Vulnerability Detection
Keyu Man, Zhongjie Wang, Yu Hao, Shenghan Zheng, Xin'an Zhou, Yue Cao, Zhiyun Qian
摘要
Network side-channel attacks have recently been highlighted due to their severity and elusive nature. For example, SADDNS attacks allow an off-path attacker to launch cache poisoning attacks leveraging network side channels. Due to the subtle nature of network side channels, it is challenging to identify such side channels. To this date, few automated bug discovery techniques are tailored for such vulnerabilities. Unfortunately, none of them is general and automated enough, making their impact and longer-term use limited. In this paper, we describe the first solution that aims to fill this gap. Specifically, we develop SCAD, aiming at identifying violations of the non-interference property, which are commonly understood as the root cause of network side channels. As non-interference property is a hyperproperty, it necessitates reasoning across multiple execution traces. This motivated us to develop our solution based on under-constrained and dynamic symbolic execution. The state-of-the-art solution, SCENT, applies model checking, which requires extra effort in modeling or simplifying certain parts of a network protocol, in order to scale. Unfortunately, such modeling and simplification is time-consuming, error prone, and can overlook important details, leading to missed vulnerabilities. For example, it was reported that 2.5 person-week was required to construct a self-contained using SCENT. In comparison, SCAD requires only a single person-day to perform labeling of secrets and attacker-observables, and decide the analysis scope. By applying SCAD to multiple TCP and UDP implementations, including Linux, FreeBSD, and lwIp,we find 14 network side-channels, 7 of which were previously unknown, with a false positive rate of only 17.6%. The results reveal serious vulnerabilities, including those that can be used to compromise the previously patched Linux and FreeBSD kernels, making them susceptible to SADDNS attacks or off-path TCP exploits. Our analysis concludes that the majority of the side channels cannot be found by existing solutions due to the aforementioned limitations.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick CheckingYuxiao Wu, Yunyi Zhang, Chaoyi Lu, Baojun LiuNDSS 2026 · 被引用 2 次
- WAVED: Principled Identification of Off-Path Exploitable Weak Verifications within the TCP/IP Protocol SuiteYizhou Zhao, Xuewei Feng, Min Li, Ke XuUSENIX Security 2026
它引用的顶会 Paper14
- CacheD: Identifying Cache-Based Timing Channels in Production SoftwareShuai Wang, Pei Wang, Xiao Liu, Danfeng Zhang 等USENIX Security 2017 · 被引用 130 次
- CaSym: Cache Aware Symbolic Execution for Side Channel Detection and MitigationRobert Brotzman, Shen Liu, Danfeng Zhang, Gang Tan 等S&P 2019 · 被引用 77 次
- Off-Path TCP Exploits: Global Rate Limit Considered DangerousYue Cao, Zhiyun Qian, Zhongjie Wang, Tuan Dao 等USENIX Security 2016 · 被引用 74 次
- DNS Cache Poisoning Attack Reloaded: Revolutions with Side ChannelsKeyu Man, Zhiyun Qian, Zhongjie Wang, Xiaofeng Zheng 等CCS 2020 · 被引用 62 次
- Unveiling your keystrokes: A Cache-based Side-channel Attack on Graphics LibrariesDaimeng Wang, Ajaya Neupane, Zhiyun Qian, Nael B. Abu-Ghazaleh 等NDSS 2019 · 被引用 47 次
相关 Paper
- Principled Unearthing of TCP Side Channel VulnerabilitiesYue Cao, Zhongjie Wang, Zhiyun Qian, Chengyu Song 等CCS 2019 · 被引用 20 次
- Athena: Analyzing and Quantifying Side Channels of Transport Layer ProtocolsFeiyang Yu, Quan Zhou, Syed Rafiul Hussain, Danfeng ZhangUSENIX Security 2024
- Precisely Characterizing Security Impact in a Flood of Patches via Symbolic Rule ComparisonQiushi Wu, Yang He, Stephen McCamant, Kangjie LuNDSS 2020
- Identifying Cache-Based Side Channels through Secret-Augmented Abstract InterpretationShuai Wang, Yuyan Bao, Xiao Liu, Pei Wang 等USENIX Security 2019 · 被引用 57 次
- DNS Cache Poisoning Attack: Resurrections with Side ChannelsKeyu Man, Xin'an Zhou, Zhiyun QianCCS 2021 · 被引用 33 次
