• Home
  • Search
  • Symbolic path cost analysis for side-channel detection
  • Cite Icon26
  • https://doi.org/10.1145/3213846.3213867Copy DOI Icon

Symbolic path cost analysis for side-channel detection

  • Jul 12, 2018
  • Tegan Brennan +3 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Side-channels in software are an increasingly significant threat to the confidentiality of private user information, and the static detection of such vulnerabilities is a key challenge in secure software development. In this paper, we introduce a new technique for scalable detection of side- channels in software. Given a program and a cost model for a side-channel (such as time or memory usage), we decompose the control flow graph of the program into nested branch and loop components, and compositionally assign a symbolic cost expression to each component. Symbolic cost expressions provide an over-approximation of all possible observable cost values that components can generate. Queries to a satisfiability solver on the difference between possible cost values of a component allow us to detect the presence of imbalanced paths (with respect to observable cost) through the control flow graph. When combined with taint analysis that identifies conditional statements that depend on secret information, our technique answers the following question: Does there exist a pair of paths in the program's control flow graph, differing only on branch conditions influenced by the secret, that differ in observable side-channel value by more than some given threshold? Additional optimization queries allow us to identify the minimal number of loop iterations necessary for the above to hold or the maximal cost difference between paths in the graph. We perform symbolic execution based feasibility analyses to eliminate control flow paths that are infeasible. We implemented our techniques in a prototype, and we demonstrate its favourable performance against state-of-the-art tools as well as its effectiveness and scalability on a set of sizable, realistic Java server-client and peer-to-peer applications.

Similar Papers
  • Conference Article
  • Citations6

Efficient detection and exploitation of infeasible paths for software timing analysis

  • Jan 01, 2006
  • Proceedings - ACM IEEE Design Automation Conference
  • V Suhendra +3
  • Conference Article
  • Citations2

MazeRunner: Evaluating the Attack Surface of Control-Flow Integrity Policies

  • Oct 01, 2021
  • Dongrui Zeng +2
  • Conference Article
  • Citations6

A Control Flow Graph Reconstruction Method from Binaries Based on XML

  • Jan 01, 2009
  • Wenjian Yin +4
  • Research Article
  • Citations6

An analytical approach for fast and accurate design space exploration of instruction caches

  • Dec 01, 2013
  • ACM Transactions on Embedded Computing Systems
  • Yun Liang +1
  • Conference Article
  • Citations1

A Memory-Based Abstraction Approach to Handle Obfuscation in Polymorphic Virus

  • Dec 01, 2012
  • Binh T Nguyen +2
  • Conference Article
  • Citations3

Comparing Control Flow Graphs of Binary Programs through Match Propagation

  • Jul 01, 2014
  • Hyun-Il Lim
  • Conference Article
  • Citations2

BCFA

  • Jun 27, 2020
  • Ramanathan Ramu +3
  • Conference Article
  • Citations22

Adaptive Call-Site Sensitive Control Flow Integrity

  • Jun 01, 2019
  • Mustakimur Khandaker +5
  • Dissertation

Trust, transforms, and control flow: A graph-theoretic method to verifying source and binary control flow equivalence

  • Jan 01, 2021
  • Ryan Christopher Goluch
  • Conference Article
  • Citations25

Towards regression test selection for AspectJ programs

  • Jul 20, 2006
  • Jianjun Zhao +2
  • Research Article
  • Citations6

Constructing PLC Binary Program Model for Detection Purposes

  • Sep 01, 2018
  • Journal of Physics: Conference Series
  • Tianyou Chang +3
  • Research Article
  • Citations17

MalGNE: Enhancing the Performance and Efficiency of CFG-Based Malware Detector by Graph Node Embedding in Low Dimension Space

  • Jan 01, 2024
  • IEEE Transactions on Information Forensics and Security
  • Hao Peng +8
  • Book Chapter
  • Citations5

Generating Test Data for Path Coverage Based Testing Using Genetic Algorithms

  • Sep 24, 2013
  • Madhumita Panda +1
  • Research Article

A structure based measurement of software

  • Feb 21, 1989
  • Narayan C Debnath
  • Conference Article
  • Citations23

Automatically computing path complexity of programs

  • Aug 30, 2015
  • Lucas Bang +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.