SCANDALee: A side-ChANnel-based DisAssembLer using local electromagnetic emanations

SCANDALee: A side-ChANnel-based DisAssembLer using local electromagnetic emanations
复制标题

DOI:
10.7873/date.2015.0639
复制
发表时间:
2015-03
期刊:
2015 Design, Automation & Test in Europe Conference & Exhibition (DATE)
影响因子:
--
通讯作者:
Daehyun Strobel;Florian Bache;David F. Oswald;Falk Schellenberg;C. Paar
Daehyun Strobel;Florian Bache;David F. Oswald;Falk Schellenberg;C. Paar
中科院分区:
其他
文献类型:
--
作者:
Daehyun Strobel;Florian Bache;David F. Oswald;Falk Schellenberg;C. Paar

文献摘要

被引文献

相似文献

在过去的十五年里,侧通道分析已经成为科学界和工业界的一个公认的话题。有些令人惊讶的是,绝大多数关于侧信道分析的工作都局限于通过恢复密钥来攻击加密实现的“用例”。在这方面的贡献,我们展示了如何侧通道分析可以用于提取代码从嵌入式系统的CPU的电磁辐射的基础上。在安全社区内外有许多应用程序都需要这样做。在密码学中,例如,用于恢复专有密码和安全协议。另一个广泛的应用领域是通用安全和逆向工程,例如,用于检测固件的IP违规或用于在没有调试接口或专用接口时调试嵌入式系统。我们的方法的一个核心特点是,我们采取局部电磁测量,在空间上分布在被分析的IC。考虑到这些多个输入,我们将代码提取建模为一个分类问题,并使用监督学习算法解决。我们应用线性判别分析的变体来区分多个类别。与之前报告的指令识别率在40- 70%之间的方法相比,我们的方法检测到超过95%的测试代码指令,接近90%的真实代码指令。因此,这些方法非常适合在实践中使用。我们的方法执行动态代码识别,这既有优点(只有实际执行的程序部分进行观察),但也有局限性(罕见的代码执行难以观察)。
Side-channel analysis has become a well-established topic in the scientific community and industry over the last one and a half decade. Somewhat surprisingly, the vast majority of work on side-channel analysis has been restricted to the “use case” of attacking cryptographic implementations through the recovery of keys. In this contribution, we show how side-channel analysis can be used for extracting code from embedded systems based on a CPU's electromagnetic emanation. There are many applications within and outside the security community where this is desirable. In cryptography, it can, e.g., be used for recovering proprietary ciphers and security protocols. Another broad application field is general security and reverse engineering, e.g., for detecting IP violations of firmware or for debugging embedded systems when there is no debug interface or it is proprietary. A core feature of our approach is that we take localized electromagnetic measurements that are spatially distributed over the IC being analyzed. Given these multiple inputs, we model code extraction as a classification problem that we solve with supervised learning algorithms. We apply a variant of linear discriminant analysis to distinguish between the multiple classes. In contrast to previous approaches, which reported instruction recognition rates between 40-70%, our approach detects more than 95% of all instructions for test code, and close to 90% for real-world code. The methods are thus very relevant for use in practice. Our method performs dynamic code recognition, which has both advantages (only the program parts that are actually executed are observed) but also limitations (rare code executions are difficult to observe).