首页> 外文会议>International Conference on Codes, Cryptology and Information Security >Virtual Security Evaluation An Operational Methodology for Side-Channel Leakage Detection at Source-Code Level
【24h】

Virtual Security Evaluation An Operational Methodology for Side-Channel Leakage Detection at Source-Code Level

机译:虚拟安全评估:在源代码级别进行边通道泄漏检测的一种操作方法

获取原文

摘要

'An ounce of prevention is worth a pound of cure'. This paper presents a methodology to detect side-channel leakage at source-code level. It leverages simple tests performed on noise-less traces of execution, and returns to the developer accurate information about the security issues. The feedback is in terms of location (where in code, when in time), in terms of security severity (amount and duration of leakage), and most importantly, in terms of possible reason for the leakage. After the source code (and subsequently the compiled code) has been sanitized, attack attempts complement the methodology to test the implementation against realistic exploitations. This last steps allows to validate whether the tolerated leakages during the sanitizing stage are indeed benign.
机译:“一分预防胜于一磅治疗”。本文提出了一种在源代码级别检测旁道泄漏的方法。它利用在无噪声执行痕迹上执行的简单测试,并向开发人员返回有关安全问题的准确信息。反馈是根据位置(代码中的时间),安全严重性(泄漏的数量和持续时间),最重要的是,根据泄漏的可能原因。在对源代码(以及随后的已编译代码)进行清理之后,攻击尝试将对方法进行补充,以针对实际攻击对实现进行测试。最后一步可以验证消毒阶段所容许的泄漏是否确实良性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号