MicroWalk: A Framework for Finding Side Channels in Binaries
arXiv:1808.05575 · doi:10.1145/3274694.3274741
Abstract
Microarchitectural side channels expose unprotected software to information leakage attacks where a software adversary is able to track runtime behavior of a benign process and steal secrets such as cryptographic keys. As suggested by incremental software patches for the RSA algorithm against variants of side-channel attacks within different versions of cryptographic libraries, protecting security-critical algorithms against side channels is an intricate task. Software protections avoid leakages by operating in constant time with a uniform resource usage pattern independent of the processed secret. In this respect, automated testing and verification of software binaries for leakage-free behavior is of importance, particularly when the source code is not available. In this work, we propose a novel technique based on Dynamic Binary Instrumentation and Mutual Information Analysis to efficiently locate and quantify memory based and control-flow based microarchitectural leakages. We develop a software framework named \tool~for side-channel analysis of binaries which can be extended to support new classes of leakage. For the first time, by utilizing \tool, we perform rigorous leakage analysis of two widely-used closed-source cryptographic libraries: \emph{Intel IPP} and \emph{Microsoft CNG}. We analyze different cryptographic implementations consisting of million instructions in about minutes of CPU time. By locating previously unknown leakages in hardened implementations, our results suggest that \tool~can efficiently find microarchitectural leakages in software binaries.
References in corpus (5)
- Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGX
- ARMageddon: Cache Attacks on Mobile Devices
- Stacco: Differentially Analyzing Side-Channel Traces for Detecting SSL/TLS Vulnerabilities in Secure Enclaves
- CacheZoom: How SGX Amplifies The Power of Cache Attacks
- Did we learn from LLC Side Channel Attacks? A Cache Leakage Detection Tool for Crypto Libraries
Cited by in corpus (19)
- Binsec/Rel: Efficient Relational Symbolic Execution for Constant-Time at Binary-Level
- FortuneTeller: Predicting Microarchitectural Attacks via Unsupervised Deep Learning
- TPM-FAIL: TPM meets Timing and Lattice Attacks
- A Hybrid Approach to Secure Function Evaluation Using SGX
- Microwalk-CI: Practical Side-Channel Analysis for JavaScript Applications
- A Survey of Microarchitectural Side-channel Vulnerabilities, Attacks and Defenses in Cryptography
- Identifying Cache-Based Side Channels through Secret-Augmented Abstract Interpretation
- Cache Refinement Type for Side-Channel Detection of Cryptographic Software
- Util::Lookup: Exploiting key decoding in cryptographic libraries
- MAMBO-V: Dynamic Side-Channel Leakage Analysis on RISC-V
- IOTLB-SC: An Accelerator-Independent Leakage Source in Modern Cloud Systems
- Breaking Bad: How Compilers Break Constant-Time Implementations
- Frontal Attack: Leaking Control-Flow in SGX via the CPU Frontend
- Towards Automated Detection of Single-Trace Side-Channel Vulnerabilities in Constant-Time Cryptographic Code
- SpecuSym: Speculative Symbolic Execution for Cache Timing Leak Detection
- From Dragondoom to Dragonstar: Side-channel Attacks and Formally Verified Implementation of WPA3 Dragonfly Handshake
- Revisiting and Evaluating Software Side-channel Vulnerabilities and Countermeasures in Cryptographic Applications
- SMaCk: Efficient Instruction Cache Attacks via Self-Modifying Code Conflicts
- CACHE SNIPER : Accurate timing control of cache evictions