Abstract
Program runtime/timing attacks exploit variations in a program's execution times to extract sensitive information from the program (e.g. encryption keys, sensitive variable data, intellectual property). State-of-the-art solutions to runtime side-channel attacks attempt to balance the execution time of the sensitive code for different control flow paths to eliminate the timing leakage. However, during the mitigation process, most techniques do not consider the underlying hardware/device on which the target program is supposed to run on. This can lead to over-fixing (unnecessary extra operations), under-fixing (not solving the imbalance properly), and even failures. We propose DISARM, a joint hardware-software methodology (unlike any existing solution) for mitigating runtime side-channel vulnerabilities that utilizes timing values from real embedded devices to generate targeted software fixes. We implement DISARM to support C/C++/Java source codes and validate it across 22 standard benchmarks. DISARM outperforms state-of-the-art solutions such as PENDULUM and DifFuzzaR in terms of execution time overhead, code size overhead, and correctness on five different embedded/edge devices.
| Original language | English |
|---|---|
| Pages (from-to) | 6316-6331 |
| Number of pages | 16 |
| Journal | IEEE Transactions on Information Forensics and Security |
| Volume | 21 |
| DOIs | |
| State | Published - 2026 |
Funding
This work was supported in part by University of Tennessee-Battelle (UT-Battelle), Limited Liability Company (LLC), with U.S. Department of Energy (DOE), under Contract DE-AC05-00OR22725; and in part by U.S. Army Engineer Research and Development Center Information Technology Laboratory (ITL) via Other Transaction under Agreement W15QKN-17-9-5555 and Agreement C5-23-1003.
Keywords
- Timing/runtime side-channel
- automated code repair
- energy efficient cybersecurity
- hardware-software co-security
Fingerprint
Dive into the research topics of 'DISARM: Target Electronic Device Informed Mitigation of Software Runtime Side-Channel Vulnerabilities'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver