Beat the Heat: Syscall Attack Detection via Thermal Side Channel

Author:

Vasilas Teodora1ORCID,Bacila Claudiu1,Brad Remus1ORCID

Affiliation:

1. Department of Computer Science, Electrical and Electronics Engineering, University of Sibiu, 4 Emil Cioran Street, 550025 Sibiu, Romania

Abstract

As the complexity and integration of electronic devices increase, understanding and mitigating side-channel vulnerabilities will remain a critical area of cybersecurity research. The new and intriguing software-based thermal side-channel attacks and countermeasures use thermal emissions from a device to extract or defend sensitive information, by reading information from the built-in thermal sensors via software. This work extends the Hot-n-Cold anomaly detection technique, applying it in circumstances much closer to the real-world computational environments by detecting irregularities in the Linux command behavior through CPU temperature monitoring. The novelty of this approach lies in the introduction of five types of noise across the CPU, including moving files, performing extended math computations, playing songs, and browsing the web while the attack detector is running. We employed Hot-n-Cold to monitor core temperatures on three types of CPUs utilizing two commonly used Linux terminal commands, ls and chmod. The results show a high correlation, approaching 0.96, between the original Linux command and a crafted command, augmented with vulnerable system calls. Additionally, a Machine Learning algorithm was used to classify whether a thermal trace is augmented or not, with an accuracy of up to 88%. This research demonstrates the potential for detecting attacks through thermal sensors even when there are different types of noise in the CPU, simulating a real-world scenario.

Publisher

MDPI AG

Reference38 articles.

1. ThermalBleed: A practical thermal side-channel attack;Kim;IEEE Access,2022

2. Vasilas, T., Jakobsche, T., and Ciorba, F.M. (2023, January 10–12). Hot-n-Cold: Mapping the Syscall Attack Surface Using Thermal Side Channels. Proceedings of the 2023 22nd International Symposium on Parallel and Distributed Computing (ISPDC), Bucharest, Romania.

3. Marek, R. (2024, May 29). Kernel Driver Coretemp. Available online: https://docs.kernel.org/hwmon/coretemp.html.

4. (2024, May 29). Common Vulnerabilities and Exposures. Available online: https://cve.mitre.org/cve/search_cve_list.html.

5. Masti, R.J., Rai, D., Ranganathan, A., Müller, C., Thiele, L., and Capkun, S. (2015, January 12–14). Thermal covert channels on multi-core platforms. Proceedings of the 24th USENIX Security Symposium (USENIX Security 15), Washington, DC, USA.

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3