Targeted Black-Box Side-Channel Mitigation for IoT

被引:0
|
作者
Kadron, Ismet Burak [1 ]
Shou, Chaofan [1 ]
O'Mahony, Emily [1 ]
Vural, Yilmaz [1 ]
Bultan, Tevfik [1 ]
机构
[1] Univ Calif Santa Barbara, Santa Barbara, CA 93106 USA
关键词
Side-channel analysis; Network traffic analysis; Internet of Things;
D O I
10.1145/3567445.3567447
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In this paper we present techniques for generating targeted mitigation strategies for network side-channel vulnerabilities in IoT applications. Our tool IoTPatch profiles the target IoT application by capturing the network traffic and labeling the network traces with the corresponding user actions. It extracts features such as packet sizes and times from the captured traces, and quantifies the information leakage by modeling the distribution of feature values. In order to mitigate the side-channel vulnerabilities, IoTPatch uses the information leakage measure over features to prioritize specific features and synthesizes a packet padding and delaying strategy based on an objective function for minimizing information leakage and time and space overhead. IoTPatch provides a tunable mitigation strategy where the trade-off between the information leakage and performance overhead can be adjusted to accommodate needs of different applications. We evaluate IoTPatch on three network benchmarks and demonstrate that IoTPatch can discover and quantify the information leakage and synthesize a set of Pareto optimal mitigation strategies performing better than the prior work in terms of reducing leakage and overhead.
引用
收藏
页码:49 / 56
页数:8
相关论文
共 50 条
  • [1] Adversarial Black-Box Attacks with Timing Side-Channel Leakage
    Nakai, Tsunato
    Suzuki, Daisuke
    Omatsu, Fumio
    Fujino, Takeshi
    [J]. IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2021, E104A (01) : 143 - 151
  • [2] Automated Black-Box Detection of Side-Channel Vulnerabilities in Web Applications
    Chapman, Peter
    Evans, David
    [J]. PROCEEDINGS OF THE 18TH ACM CONFERENCE ON COMPUTER & COMMUNICATIONS SECURITY (CCS 11), 2011, : 263 - 274
  • [3] Automated Side-Channel Attacks using Black-Box Neural Architecture Search
    Gupta, Pritha
    Drees, Jan Peter
    Huellermeier, Eyke
    [J]. 18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023, 2023,
  • [4] When Side-Channel Attacks Break the Black-Box Property of Embedded Artificial Intelligence
    Coqueret, Benoit
    Carbone, Mathieu
    Sentieys, Olivier
    Zaid, Gabriel
    [J]. PROCEEDINGS OF THE 16TH ACM WORKSHOP ON ARTIFICIAL INTELLIGENCE AND SECURITY, AISEC 2023, 2023, : 127 - 138
  • [5] Peek into the Black-Box: Interpretable Neural Network using SAT Equations in Side-Channel Analysis
    Yap, Trevor
    Benamira, Adrien
    Bhasin, Shivam
    Peyrin, Thomas
    [J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2023, 2023 (02): : 24 - 53
  • [6] Evaluating and Designing against Side-Channel Leakage: White Box or Black Box?
    Standaert, Francois-Xavier
    [J]. PROCEEDINGS OF THE 2021 ACM WORKSHOP ON INFORMATION HIDING AND MULTIMEDIA SECURITY, IH&MMSEC 2021, 2021, : 1 - 1
  • [7] Predictive Black-Box Mitigation of Timing Channels
    Askarov, Aslan
    Zhang, Danfeng
    Myers, Andrew C.
    [J]. PROCEEDINGS OF THE 17TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'10), 2010, : 297 - 307
  • [8] μLeech: A Side-Channel Evaluation Platform for IoT
    Moukarzel, Michael
    Eisenbarth, Thomas
    Sunar, Berk
    [J]. 2017 IEEE 60TH INTERNATIONAL MIDWEST SYMPOSIUM ON CIRCUITS AND SYSTEMS (MWSCAS), 2017, : 25 - 28
  • [9] How to fool a black box machine learning based side-channel security evaluation
    Charles-Henry Bertrand Van Ouytsel
    Olivier Bronchain
    Gaëtan Cassiers
    François-Xavier Standaert
    [J]. Cryptography and Communications, 2021, 13 : 573 - 585
  • [10] How to fool a black box machine learning based side-channel security evaluation
    Bertrand Van Ouytsel, Charles-Henry
    Bronchain, Olivier
    Cassiers, Gaetan
    Standaert, Francois-Xavier
    [J]. CRYPTOGRAPHY AND COMMUNICATIONS-DISCRETE-STRUCTURES BOOLEAN FUNCTIONS AND SEQUENCES, 2021, 13 (04): : 573 - 585