SAMVA: Static Analysis for Multi-Fault Attack Paths Determination - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2023

SAMVA: Static Analysis for Multi-Fault Attack Paths Determination

Résumé

Multi-fault injection attacks are powerful since they allow to bypass software security mechanisms of embedded devices. Assessing the vulnerability of an application while considering multiple faults with various effects is an open problem due to the size of the fault space to explore. We propose SAMVA, a framework for efficiently searching vulnerabilities of applications in presence of multiple instruction-skip faults with various widths. SAMVA relies solely on static analysis to determine attack paths in a binary code. It is configurable with the fault injection capacity of the attacker and the attacker's objective. We evaluate the proposed approach on eight PIN verification programs containing various software countermeasures. Our framework finds numerous attack paths, even for the most hardened version, in very limited time.
Fichier principal
Vignette du fichier
SAMVA___Cosade23-8.pdf (908.38 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03980128 , version 1 (09-02-2023)

Identifiants

Citer

Antoine Gicquel, Damien Hardy, Karine Heydemann, Erven Rohou. SAMVA: Static Analysis for Multi-Fault Attack Paths Determination. COSADE 2023 - 14th International Workshop on Constructive Side-Channel Analysis and Secure Design, Apr 2023, Munich (Allemagne), Germany. pp.3-22, ⟨10.1007/978-3-031-29497-6_1⟩. ⟨hal-03980128⟩
269 Consultations
227 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More