Statistical Analysis of the Impact of Bit-Flips in Security Critical Code

Research output: Contribution to book/anthology/report/conference proceedingArticle in proceedingResearchpeer-review

Abstract

Fault injection is a sophisticated attack in which an attacker may sidestep security of an application by inducing bit-flips in the underlying platform. These attacks are typically performed by tampering with the system hardware, but recent RowHammer attacks have shown that bit-flips can be induced predictably and on a large scale through software alone [12]. It is practically impossible for a developer to evaluate and assess if and how much an application is vulnerable to RowHammer attacks. In this paper, we leverage statistical model checking (SMC) to help with these challenges by modelling and analysing potential effects of bit-flips as well as measure the efficacy of proposed mitigation. We illustrate our approach on SUDO, one of several security critical applications recently targeted in the RowHammer-based Mayhem attacks [1].
Original languageEnglish
Title of host publicationBridging the Gap Between AI and Reality : Second International Conference, AISoLA 2024, Crete, Greece, October 30 – November 3, 2024, Proceedings
PublisherSpringer
Publication dateDec 2024
Edition1
Pages379-397
ISBN (Print)978-3-031-75433-3
ISBN (Electronic)978-3-031-75434-0
DOIs
Publication statusPublished - Dec 2024
EventAISoLA 2024
- Crete, Greece
Duration: 30 Oct 20243 Nov 2024

Conference

ConferenceAISoLA 2024
Country/TerritoryGreece
CityCrete
Period30/10/202403/11/2024
SeriesLecture Notes in Computer Science
Volume15217
ISSN0302-9743

Fingerprint

Dive into the research topics of 'Statistical Analysis of the Impact of Bit-Flips in Security Critical Code'. Together they form a unique fingerprint.

Cite this