首页> 外文会议>IEEE Symposium on Security and Privacy >CaSym: Cache Aware Symbolic Execution for Side Channel Detection and Mitigation
【24h】

CaSym: Cache Aware Symbolic Execution for Side Channel Detection and Mitigation

机译:CaSym:用于边通道检测和缓解的缓存感知符号执行

获取原文

摘要

Cache-based side channels are becoming an important attack vector through which secret information can be leaked to malicious parties. implementations and Previous work on cache-based side channel detection, however, suffers from the code coverage problem or does not provide diagnostic information that is crucial for applying mitigation techniques to vulnerable software. We propose CaSym, a cache-aware symbolic execution to identify and report precise information about where side channels occur in an input program. Compared with existing work, CaSym provides several unique features: (1) CaSym enables verification against various attack models and cache models, (2) unlike many symbolic-execution systems for bug finding, CaSym verifies all program execution paths in a sound way, (3) CaSym uses two novel abstract cache models that provide good balance between analysis scalability and precision, and (4) CaSym provides sufficient information on where and how to mitigate the identified side channels through techniques including preloading and pinning. Evaluation on a set of crypto and database benchmarks shows that CaSym is effective at identifying and mitigating side channels, with reasonable efficiency.
机译:基于缓存的辅助通道正在成为重要的攻击媒介,通过该渠道,机密信息可以泄露给恶意方。但是,有关基于缓存的边信道检测的实现和以前的工作会遭受代码覆盖问题或无法提供诊断信息,而诊断信息对于将缓解技术应用于易受攻击的软件至关重要。我们建议使用CaSym,这是一种可识别高速缓存的符号执行程序,用于识别和报告有关输入程序中何处出现辅助通道的精确信息。与现有工作相比,CaSym提供了几个独特的功能:(1)CaSym支持针对各种攻击模型和缓存模型进行验证;(2)与许多用于查找错误的符号执行系统不同,CaSym以合理的方式验证所有程序执行路径,( 3)CaSym使用两个新颖的抽象缓存模型,它们在分析可伸缩性和精度之间提供了良好的平衡,并且(4)CaSym通过有关预加载和固定的技术,提供了有关在何处以及如何缓解所标识的副信道的足够信息。对一组加密和数据库基准进行的评估表明,CaSym可以有效地识别和缓解边信道,并且效率合理。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号