Systematic Classification of Side-Channel Attacks: A Case Study for Mobile Devices
arXiv:1611.03748 · doi:10.1109/COMST.2017.2779824
Abstract
Side-channel attacks on mobile devices have gained increasing attention since their introduction in 2007. While traditional side-channel attacks, such as power analysis attacks and electromagnetic analysis attacks, required physical presence of the attacker as well as expensive equipment, an (unprivileged) application is all it takes to exploit the leaking information on modern mobile devices. Given the vast amount of sensitive information that are stored on smartphones, the ramifications of side-channel attacks affect both the security and privacy of users and their devices. In this paper, we propose a new categorization system for side-channel attacks, which is necessary as side-channel attacks have evolved significantly since their scientific investigations during the smart card era in the 1990s. Our proposed classification system allows to analyze side-channel attacks systematically, and facilitates the development of novel countermeasures. Besides this new categorization system, the extensive survey of existing attacks and attack strategies provides valuable insights into the evolving field of side-channel attacks, especially when focusing on mobile devices. We conclude by discussing open issues and challenges in this context and outline possible future research directions.
Cited by in corpus (12)
- A Survey on Large Language Model (LLM) Security and Privacy: The Good, the Bad, and the Ugly
- A Survey of Electromagnetic Side-Channel Attacks and Discussion on their Case-Progressing Potential for Digital Forensics
- A Survey of Security in UAVs and FANETs: Issues, Threats, Analysis of Attacks, and Solutions
- SoK: Exploring the State of the Art and the Future Potential of Artificial Intelligence in Digital Forensic Investigation
- Taxonomy and Challenges of Out-of-Band Signal Injection Attacks and Defenses
- Fault Attacks on Secure Embedded Software: Threats, Design and Evaluation
- Physical Fault Injection and Side-Channel Attacks on Mobile Devices: A Comprehensive Analysis
- Physical Side-Channel Attacks on Embedded Neural Networks: A Survey
- Wireless Charging Power Side-Channel Attacks
- Embodied AI with Foundation Models for Mobile Service Robots: A Systematic Review
- EavesDroid: Eavesdropping User Behaviors via OS Side-Channels on Smartphones
- Nowhere to Hide: Cross-modal Identity Leakage between Biometrics and Devices