Time and Order: Towards Automatically Identifying Side-Channel Vulnerabilities in Enclave Binaries

Time and Order: Towards Automatically Identifying Side-Channel Vulnerabilities in Enclave Binaries
复制标题

DOI:
--
复制
发表时间:
2019
期刊:
--
影响因子:
--
通讯作者:
Wubing Wang;Yinqian Zhang;Zhiqiang Lin
Wubing Wang;Yinqian Zhang;Zhiqiang Lin
中科院分区:
其他
文献类型:
--
作者:
Wubing Wang;Yinqian Zhang;Zhiqiang Lin

文献摘要

被引文献

相似文献

虽然英特尔SGX为在安全区内运行的程序提供了机密性和完整性保证,但旁路通道仍然是SGX安全性的主要问题。之前的工作广泛考虑了使用各种攻击向量和技术在页面、缓存和分支级别针对SGX飞地的侧通道攻击。这些研究中的大多数仅利用了存储器访问模式的“顺序”属性(例如,页面访问序列)作为侧信道。然而,存储器访问模式的另一个属性“时间”,它表征了两次特定存储器访问之间的间隔,大部分都未被探索。在本文中,我们提出了一个NABLEPS,一个工具来自动检测侧通道漏洞的飞地二进制文件,同时考虑顺序和时间。NABLEPS利用concolic执行和模糊技术为任意安全区程序生成输入集,使用英特尔PT构建执行跟踪的扩展动态控制流图表示,并使用图形分析自动分析和识别侧通道漏洞。
While Intel SGX provides confidentiality and integrity guar-antees to programs running inside enclaves, side channels remain a primary concern of SGX security. Previous works have broadly considered the side-channel attacks against SGX enclaves at the levels of pages, caches, and branches, using a variety of attack vectors and techniques. Most of these studies have only exploited the “order” attribute of the memory access patterns (e.g., sequences of page accesses) as side channels. However, the other attribute of memory access patterns, “time”, which characterizes the interval between two specific memory accesses, is mostly unexplored. In this paper, we present A NABLEPS , a tool to automate the detection of side-channel vulnerabilities in enclave binaries, considering both order and time. A NABLEPS leverages concolic execution and fuzzing techniques to generate input sets for an arbitrary enclave program, constructing extended dynamic control-flow graph representation of execution traces using Intel PT, and automatically analyzing and identifying side-channel vulnerabilities using graph analysis.