Feedback-driven side-channel analysis for networked applications

Feedback-driven side-channel analysis for networked applications
复制标题

DOI:
10.1145/3395363.3397365
复制
发表时间:
2020-07
期刊:
Proceedings of the 29th ACM SIGSOFT International Symposium on Software Testing and Analysis
影响因子:
--
通讯作者:
Ismet Burak Kadron;Nicolás Rosner;T. Bultan
Ismet Burak Kadron;Nicolás Rosner;T. Bultan
中科院分区:
其他
文献类型:
--
作者:
Ismet Burak Kadron;Nicolás Rosner;T. Bultan

文献摘要

相似文献

软件系统中的信息泄漏是一个日益重要的问题。网络应用程序即使使用加密也可能泄漏敏感信息。例如,网络数据包的某些特征,如其大小、定时和方向,即使对于加密流量也是可见的。这些特征中的模式可以用作侧通道来提取有关应用程序访问的秘密值的信息。在本文中,我们提出了一个新的工具,称为AutoFeed的检测和量化信息泄漏,由于侧通道在网络软件应用程序。AutoFeed分析目标系统,并自动探索输入空间,探索可能泄漏信息的输出功能的空间,量化信息泄漏,并识别顶部泄漏功能。给定一组输入变异器和用户提供的少量初始输入,AutoFeed迭代地变异输入并定期更新其泄漏估计,以识别泄漏有关感兴趣秘密的最大量信息的特征。AutoFeed使用一个反馈循环进行增量分析,并使用一个停止标准,当顶部泄漏特征的泄漏估计收敛时,该标准终止分析。AutoFeed还自动为mutator分配权重,以便将输入空间的搜索集中在探索与泄漏量化相关的维度上。我们的基准测试的实验评估表明,AutoFeed是有效的检测和量化网络应用程序中的信息泄漏。
Information leakage in software systems is a problem of growing importance. Networked applications can leak sensitive information even when they use encryption. For example, some characteristics of network packets, such as their size, timing and direction, are visible even for encrypted traffic. Patterns in these characteristics can be leveraged as side channels to extract information about secret values accessed by the application. In this paper, we present a new tool called AutoFeed for detecting and quantifying information leakage due to side channels in networked software applications. AutoFeed profiles the target system and automatically explores the input space, explores the space of output features that may leak information, quantifies the information leakage, and identifies the top-leaking features. Given a set of input mutators and a small number of initial inputs provided by the user, AutoFeed iteratively mutates inputs and periodically updates its leakage estimations to identify the features that leak the greatest amount of information about the secret of interest. AutoFeed uses a feedback loop for incremental profiling, and a stopping criterion that terminates the analysis when the leakage estimation for the top-leaking features converges. AutoFeed also automatically assigns weights to mutators in order to focus the search of the input space on exploring dimensions that are relevant to the leakage quantification. Our experimental evaluation on the benchmarks shows that AutoFeed is effective in detecting and quantifying information leaks in networked applications.