ThermalBleed: A Practical Thermal Side-Channel Attack

被引:5
|
作者
Kim, Taehun [1 ]
Shin, Youngjoo [1 ]
机构
[1] Korea Univ, Sch Cybersecur, Seoul 02841, South Korea
关键词
Thermal analysis; Temperature sensors; Side-channel attacks; Monitoring; Temperature measurement; Linux; Kernel; Breaking KASLR; digital thermal sensor; thermal side-channel attack;
D O I
10.1109/ACCESS.2022.3156596
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Modern OSs expose an interface for monitoring CPU temperature to unprivileged users for effective user decision-based thermal management. Due to the low sampling rate and resolution, thermal sensors have generally been restricted to the construction of covert channels. However, exposing the thermal interface to unprivileged users may be problematic, because the heat emission inside a CPU core is affected by program execution on the core; an attacker may be able to infer the secret information of the program by exploiting the thermal interface as a side-channel. In this paper, we extensively analyze digital thermal sensors in Intel CPUs and show that it is possible to implement a software-based thermal side-channel attack. Specifically, by analyzing some properties of the thermal sensors, we inferred that the thermal sensor makes it possible to distinguish between a cache hit and a physical memory access in memory load operations. Based on the analysis results, we implement ThermalBleed, a thermal side-channel attack that breaks kernel address space layout randomization (KASLR) in Linux systems. Moreover, by conducting an in-depth analysis, we identify useful hidden properties of the Intel thermal sensors. Our analysis establishes a stepping stone to build a more precise and effective thermal side-channel attack in the future. To the best of our knowledge, this is the first work that extends a thermal covert channel to a practical side-channel attack by exploring the properties of Intel digital thermal sensors.
引用
收藏
页码:25718 / 25731
页数:14
相关论文
共 50 条
  • [21] Iterative side-channel cube attack on KeeLoq
    Ma, Yunfei
    Wang, Tao
    Chen, Hao
    Lei, Dong
    [J]. PROCEEDINGS OF 2016 SIXTH INTERNATIONAL CONFERENCE ON INSTRUMENTATION & MEASUREMENT, COMPUTER, COMMUNICATION AND CONTROL (IMCCC 2016), 2016, : 53 - 56
  • [22] A Novel Side-Channel Timing Attack on GPUs
    Jiang, Zhen Hang
    Fei, Yunsi
    Kaeli, David
    [J]. PROCEEDINGS OF THE GREAT LAKES SYMPOSIUM ON VLSI 2017 (GLSVLSI' 17), 2017, : 167 - 172
  • [23] Attack of the Knights: A Non Uniform Cache Side-Channel Attack
    Mahmud, Farabi
    Kim, Sungkeun
    Chawla, Harpreet Singh
    Kim, E. J.
    Tsai, Chia-Che
    Muzahid, Abdullah
    [J]. 39TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2023, 2023, : 691 - 703
  • [24] 'Unified Side-Channel Attack - Model' (USCA-M): An Extension with Biometrics Side-Channel Type
    Johnson, Andrew
    Ward, Richard
    [J]. 2022 10TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSICS AND SECURITY (ISDFS), 2022,
  • [25] 'Unified Side-Channel Attack - Model' (USCA-M): An Extension with Biometrics Side-Channel Type
    Johnson, Andrew
    Ward, Richard
    [J]. 10th International Symposium on Digital Forensics and Security, ISDFS 2022, 2022,
  • [26] Practical Side-Channel Attack on Free-Space QKD Systems With Misaligned Sources and Countermeasures
    Arteaga-Diaz, Pablo
    Cano, Daniel
    Fernandez, Veronica
    [J]. IEEE ACCESS, 2022, 10 : 82697 - 82705
  • [27] Cache Side-Channel Attack on Mail User Agent
    Kim, Hodong
    Yoon, Hyundo
    Shin, Youngjoo
    Hur, Junbeom
    [J]. 2020 34TH INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN 2020), 2020, : 236 - 238
  • [28] Side-Channel Gray-Box Attack for DNNs
    Xiang, Yun
    Xu, Yongchao
    Li, Yingjie
    Ma, Wen
    Xuan, Qi
    Liu, Yi
    [J]. IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS II-EXPRESS BRIEFS, 2021, 68 (01) : 501 - 505
  • [29] A Key Update Scheme for Side-Channel Attack Mitigation
    Gui, Yutian
    Tamore, Suyash Mohan
    Siddiqui, Ali Shuja
    Saqib, Fareena
    [J]. 2019 IEEE 16TH INTERNATIONAL CONFERENCE ON SMART CITIES: IMPROVING QUALITY OF LIFE USING ICT, IOT AND AI (IEEE HONET-ICT 2019), 2019, : 187 - 188
  • [30] Open DNN Box by Power Side-Channel Attack
    Xiang, Yun
    Chen, Zhuangzhi
    Chen, Zuohui
    Fang, Zebin
    Hao, Haiyang
    Chen, Jinyin
    Liu, Yi
    Wu, Zhefu
    Xuan, Qi
    Yang, Xiaoniu
    [J]. IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS II-EXPRESS BRIEFS, 2020, 67 (11) : 2717 - 2721