ICSE 2019
Sat 25 - Fri 31 May 2019 Montreal, QC, Canada
Wed 29 May 2019 14:20 - 14:40 at Duluth - Security 2 Chair(s): Arie van Deursen

Side-channel attacks allow an adversary to uncover secret program data by observing the behavior of a program with respect to a resource, such as execution time, consumed memory or response size. Side-channel vulnerabilities are difficult to reason about as they involve analyzing the correlations between resource usage over multiple program paths. We present DifFuzz, a fuzzing-based approach for detecting side-channel vulnerabilities related to time and space. DifFuzz automatically detects these vulnerabilities by analyzing two versions of the program and using resource-guided heuristics to find inputs that maximize the difference in resource consumption between secret-dependent paths. The methodology of DifFuzz is general and can be applied to programs written in any language. For this paper, we present an implementation that targets analysis of Java programs, and uses and extends the Kelinci and AFL fuzzers. We evaluate DifFuzz on a large number of Java programs and demonstrate that it can reveal unknown side-channel vulnerabilities in popular applications. We also show that DifFuzz compares favorably against Blazer and Themis, two state-of-the-art analysis tools for finding side-channels in Java programs.

Wed 29 May
14:00 - 15:30: Papers - Security 2 at Duluth
Chair(s): Arie van DeursenDelft University of Technology
Akond RahmanNorth Carolina State University, Chris ParninNCSU, Laurie WilliamsNorth Carolina State University
Shirin NilizadehUniversity of Texas at Arlington, Yannic NollerHumboldt-Universität zu Berlin, Corina S. PasareanuCarnegie Mellon University Silicon Valley, NASA Ames Research Center
Kalil GarrettGeorgia State University, Gabriel FerreiraCarnegie Mellon University, Limin JiaCarnegie Mellon University, Joshua SunshineCarnegie Mellon University, Christian KästnerCarnegie Mellon University
Jianbo GaoPeking University, Han LiuTsinghua University, Chao Liu, Qingshan LiPeking University, Zhi GuanPeking University, Zhong Chen
Hoa Khanh DamUniversity of Wollongong, Truyen Tran, Trang PhamDeakin University, Shien Wee NgUniversity of Wollongong, John GrundyMonash University, Aditya Ghose
