Time and Order: Towards Automatically Identifying Side-Channel Vulnerabilities in Enclave Binaries
Time and Order: Towards Automatically Identifying Side-Channel Vulnerabilities in Enclave Binaries
复制标题
DOI:
--
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
Wubing Wang;Yinqian Zhang;Zhiqiang Lin
中科院分区:
文献类型:
--
作者:
Wubing Wang;Yinqian Zhang;Zhiqiang Lin
While Intel SGX provides confidentiality and integrity guar-antees to programs running inside enclaves, side channels remain a primary concern of SGX security. Previous works have broadly considered the side-channel attacks against SGX enclaves at the levels of pages, caches, and branches, using a variety of attack vectors and techniques. Most of these studies have only exploited the “order” attribute of the memory access patterns (e.g., sequences of page accesses) as side channels. However, the other attribute of memory access patterns, “time”, which characterizes the interval between two specific memory accesses, is mostly unexplored. In this paper, we present A NABLEPS , a tool to automate the detection of side-channel vulnerabilities in enclave binaries, considering both order and time. A NABLEPS leverages concolic execution and fuzzing techniques to generate input sets for an arbitrary enclave program, constructing extended dynamic control-flow graph representation of execution traces using Intel PT, and automatically analyzing and identifying side-channel vulnerabilities using graph analysis.