Side-Channel Vulnerability Metrics: SVF vs. CSV

نویسندگان

  • John Demme
  • Simha Sethumadhavan
چکیده

Recently two papers have been published on empirically measuring side-channel leakage in processors. The first paper introduced a framework for measuring side-channel leakage called “Side-Channel Vulnerability Factor” (SVF). SVF used phase correlation between victim and attacker programs to quantify leakage. A subsequent paper opposed some of the claims made in the SVF paper and introduced another metric, “Cache Side-channel Vulnerability” (CSV). CSV uses the same concept of measuring correlation between victim and attacker, but instead proposes using direct correlation in place of phase correlation. Another major difference between SVF and CSV is the scope of leakage measurement – CSV is defined to apply to only cache leakage, whereas SVF can be applied to multiple components within a processor. The CSV authors argue that applying SVF yields conclusions which contradicts what they term to be ground truth. In addition to these differences, the two papers used different experimental setups and thus their results were not directly comparable. This paper deconstructs the differences between SVF and CSV. We first provide a general overview of side-channels and background on their modeling and measurement. We then examine the differences between SVF and CSV both quantitatively and qualitatively using a common experimental setup. Finally, building on our examination of differences, we review and rebut claims made in the CSV paper against the SVF framework and metrics.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Side-Channel Watchdog: Run-Time Evaluation of Side-Channel Vulnerability in FPGA-Based Crypto-systems

Besides security against classical cryptanalysis, its important for cryptographic implementations to have sufficient robustness against side-channel attacks. Many countermeasures have been proposed to thwart side channel attacks, especially power trace measurement based side channel attacks. Additionally, researchers have proposed several evaluation metrics to evaluate side channel security of ...

متن کامل

What Lies Ahead: Extending TVLA Testing Methodology Towards Success Rate

Evaluation of side channel vulnerability of a cryptosystem has seen significant advancement in recent years. Researchers have proposed several metrics like Test Vector Leakage Assessment Methodology (TVLA), Normalized Inter Class Variance (NICV), Signal to Noise Ratio (SNR), Guessing Entropy to determine side channel security of cryptoimplementations. Among these, TVLA has emerged as the front-...

متن کامل

FLAX: Systematic Discovery of Client-side Validation Vulnerabilities in Rich Web Applications

The complexity of the client-side components of web applications has exploded with the increase in popularity of web 2.0 applications. Today, traditional desktop applications, such as document viewers, presentation tools and chat applications are commonly available as online JavaScript applications. Previous research on web vulnerabilities has primarily concentrated on flaws in the server-side ...

متن کامل

Use of Equity Market Value for explaining Cash Flow Return on Investment (CFROI) and Created Shareholder Value (CSV) Evidence from Automotive Industry Tehran Stock Exchange

The concept of Value Creation is gaining momentum in Iran under the open regime. Iranian Companies are geared to understand and act upon the concept of Shareholder Value to stay competitive in this unfathomable and volatile environment. Most executives today understand that, the need to create shareholder value is paramount and the world’s most competitive management teams are responding to the...

متن کامل

Leak Me If You Can: Does TVLA Reveal Success Rate?

Test Vector Leakage Assessment Methodology (TVLA) has emerged as a popular side-channel testing methodology as it can detect the presence of side-channel information in leakage measurements. However, in its current form, TVLA results cannot be used to quantify side-channel vulnerability. In this paper, we extend the TVLA testing beyond its current scope. Precisely, we derive concrete relationsh...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2014