DifFuzz: Differential Fuzzing for Side-Channel Analysis
Zusammenfassung
This summary is based on our research results on ``DifFuzz: Differential Fuzzing for Side-Channel Analysis'' which was published in the proceedings of the 41st International Conference on Software Engineering. Side-channel analysis aims to investigate the risk that a potential attacker can infer any secret information through observations of the system, such as the execution time or the memory consumption. Side-channel vulnerabilities therefore represent security risks that can cause serious damage and need to be identified and repaired. DifFuzz applies differential fuzzing to identify inputs that trigger such vulnerabilities. Our fuzzing approach analyzes multiple program executions, which vary in their secret information, and uses resource-guided heuristics to identify inputs that maximize the observable cost difference between these executions. Our evaluation shows that such a dynamic analysis approach can find the same side-channel vulnerabilities as state-of-the-art static analysis techniques, and even more vulnerabilities since it does not rely on models for its analysis. Additionally, the advantage of DifFuzz compared to other techniques is not only that it can generate inputs that show a vulnerability, but that the resulting cost difference can also be used to estimate the severity of an identified vulnerability. This enables the comparing of repaired versions of an application.
- Vollständige Referenz
- BibTeX
Nilizadeh, S., Noller, Y. & Noller, Y.,
(2020).
DifFuzz: Differential Fuzzing for Side-Channel Analysis.
In:
Felderer, M., Hasselbring, W., Rabiser, R. & Jung, R.
(Hrsg.),
Software Engineering 2020.
Bonn:
Gesellschaft für Informatik e.V..
(S. 125--126).
DOI: 10.18420/SE2020_37
@inproceedings{mci/Nilizadeh2020,
author = {Nilizadeh, Shirin AND Noller, Yannic AND Noller, Yannic},
title = {DifFuzz: Differential Fuzzing for Side-Channel Analysis},
booktitle = {Software Engineering 2020},
year = {2020},
editor = {Felderer, Michael AND Hasselbring, Wilhelm AND Rabiser, Rick AND Jung, Reiner} ,
pages = { 125--126 } ,
doi = { 10.18420/SE2020_37 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
author = {Nilizadeh, Shirin AND Noller, Yannic AND Noller, Yannic},
title = {DifFuzz: Differential Fuzzing for Side-Channel Analysis},
booktitle = {Software Engineering 2020},
year = {2020},
editor = {Felderer, Michael AND Hasselbring, Wilhelm AND Rabiser, Rick AND Jung, Reiner} ,
pages = { 125--126 } ,
doi = { 10.18420/SE2020_37 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
| Dateien | Groesse | Format | Anzeige | |
|---|---|---|---|---|
| B12-02.pdf | 88.07Kb | Öffnen |
Sollte hier kein Volltext (PDF) verlinkt sein, dann kann es sein, dass dieser aus verschiedenen Gruenden (z.B. Lizenzen oder Copyright) nur in einer anderen Digital Library verfuegbar ist. Versuchen Sie in diesem Fall einen Zugriff ueber die verlinkte DOI: 10.18420/SE2020_37
Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken
Mehr Information
DOI: 10.18420/SE2020_37
ISBN: 978-3-88579-694-7
ISSN: 1617-5468
Datum: 2020
Sprache:
(en)
(en)
Typ: Text/Conference Paper

