Skip to main navigation Skip to search Skip to main content

DISARM: Target Electronic Device Informed Mitigation of Software Runtime Side-Channel Vulnerabilities

Research output: Contribution to journalArticlepeer-review

Abstract

Program runtime/timing attacks exploit variations in a program's execution times to extract sensitive information from the program (e.g. encryption keys, sensitive variable data, intellectual property). State-of-the-art solutions to runtime side-channel attacks attempt to balance the execution time of the sensitive code for different control flow paths to eliminate the timing leakage. However, during the mitigation process, most techniques do not consider the underlying hardware/device on which the target program is supposed to run on. This can lead to over-fixing (unnecessary extra operations), under-fixing (not solving the imbalance properly), and even failures. We propose DISARM, a joint hardware-software methodology (unlike any existing solution) for mitigating runtime side-channel vulnerabilities that utilizes timing values from real embedded devices to generate targeted software fixes. We implement DISARM to support C/C++/Java source codes and validate it across 22 standard benchmarks. DISARM outperforms state-of-the-art solutions such as PENDULUM and DifFuzzaR in terms of execution time overhead, code size overhead, and correctness on five different embedded/edge devices.

Original languageEnglish
Pages (from-to)6316-6331
Number of pages16
JournalIEEE Transactions on Information Forensics and Security
Volume21
DOIs
StatePublished - 2026

Funding

This work was supported in part by University of Tennessee-Battelle (UT-Battelle), Limited Liability Company (LLC), with U.S. Department of Energy (DOE), under Contract DE-AC05-00OR22725; and in part by U.S. Army Engineer Research and Development Center Information Technology Laboratory (ITL) via Other Transaction under Agreement W15QKN-17-9-5555 and Agreement C5-23-1003.

Keywords

  • Timing/runtime side-channel
  • automated code repair
  • energy efficient cybersecurity
  • hardware-software co-security

Fingerprint

Dive into the research topics of 'DISARM: Target Electronic Device Informed Mitigation of Software Runtime Side-Channel Vulnerabilities'. Together they form a unique fingerprint.

Cite this