5 papers
PowerFuzz: Power-Based Black-Box Firmware Fuzzing
Dakshina Tharindu, Sahan Sanjaya, Philip Baptist +1
Fuzzing is widely used for software and hardware verification, offering an effective alternative to random testing. While gray-box fuzzers benefit from full visibility into the sys…
SysFuSS: System-Level Firmware Fuzzing with Selective Symbolic Execution
Dakshina Tharindu, Aruna Jayasena, Prabhat Mishra
Firmware serves as the critical interface between hardware and software in computing systems, making any bugs or vulnerabilities particularly dangerous as they can cause catastroph…
Sleep Reveals the Nonce: Breaking ECDSA using Sleep-Based Power Side-Channel Vulnerability
Sahan Sanjaya, Prabhat Mishra
Security of Elliptic Curve Digital Signature Algorithm (ECDSA) depends on the secrecy of the per-signature nonce. Even partial nonce leakage can expose the long-term private key th…
Application-Specific Power Side-Channel Attacks and Countermeasures: A Survey
Sahan Sanjaya, Aruna Jayasena, Prabhat Mishra
Side-channel attacks try to extract secret information from a system by analyzing different side-channel signatures, such as power consumption, electromagnetic emanation, thermal d…
SleepWalk: Exploiting Context Switching and Residual Power for Physical Side-Channel Attacks
Sahan Sanjaya, Aruna Jayasena, Prabhat Mishra
Context switching is utilized by operating systems to change the execution context between application programs. It involves saving and restoring the states of multiple registers a…