PRESS-NEWS.org - Press Release Distribution
PRESS RELEASES DISTRIBUTION

MIT researchers devise a way to evaluate cybersecurity methods

The system analyzes the likelihood that an attacker could thwart a certain security scheme to steal secret information

2023-06-28
(Press-News.org)

A savvy hacker can obtain secret information, such as a password, by observing a computer program’s behavior, like how much time that program spends accessing the computer’s memory. 

Security approaches that completely block these “side-channel attacks” are so computationally expensive that they aren’t feasible for many real-world systems. Instead, engineers often apply what are known as obfuscation schemes that seek to limit, but not eliminate, an attacker’s ability to learn secret information.     

To help engineers and scientists better understand the effectiveness of different obfuscation schemes, MIT researchers created a framework to quantitatively evaluate how much information an attacker could learn from a victim program with an obfuscation scheme in place. 

Their framework, called Metior, allows the user to study how different victim programs, attacker strategies, and obfuscation scheme configurations affect the amount of sensitive information that is leaked. The framework could be used by engineers who develop microprocessors to evaluate the effectiveness of multiple security schemes and determine which architecture is most promising early in the chip design process. 

“Metior helps us recognize that we shouldn’t look at these security schemes in isolation. It is very tempting to analyze the effectiveness of an obfuscation scheme for one particular victim, but this doesn’t help us understand why these attacks work. Looking at things from a higher level gives us a more holistic picture of what is actually going on,” says Peter Deutsch, a graduate student and lead author of an open-access paper on Metior.

Deutsch’s co-authors include Weon Taek Na, an MIT graduate student in electrical engineering and computer science; Thomas Bourgeat PhD ’23, an assistant professor at the Swiss Federal Institute of Technology (EPFL); Joel Emer, an MIT professor of the practice in computer science and electrical engineering; and senior author Mengjia Yan, the Homer A. Burnell Career Development Assistant Professor of Electrical Engineering and Computer Science (EECS) at MIT and a member of the Computer Science and Artificial Intelligence Laboratory (CSAIL). The research was presented last week at the International Symposium on Computer Architecture.

Illuminating obfuscation

While there are many obfuscation schemes, popular approaches typically work by adding some randomization to the victim’s behavior to make it harder for an attacker to learn secrets. For instance, perhaps an obfuscation scheme involves a program accessing additional areas of the computer memory, rather than only the area it needs to access, to confuse an attacker. Others adjust how often a victim accesses memory or another a shared resource so an attacker has trouble seeing clear patterns.

But while these approaches make it harder for an attacker to succeed, some amount of information from the victim still “leaks” out. Yan and her team want to know how much. 

They had previously developed CaSA, a tool to quantify the amount of information leaked by one particular type of obfuscation scheme. But with Metior, they had more ambitious goals. The team wanted to derive a unified model that could be used to analyze any obfuscation scheme — even schemes that haven’t been developed yet.

To achieve that goal, they designed Metior to map the flow of information through an obfuscation scheme into random variables. For instance, the model maps the way a victim and an attacker access shared structures on a computer chip, like memory, into a mathematical formulation. 

One Metior derives that mathematical representation, the framework uses techniques from information theory to understand how the attacker can learn information from the victim. With those pieces in place, Metior can quantify how likely it is for an attacker to successfully guess the victim’s secret information.

“We take all of the nitty-gritty elements of this microarchitectural side-channel and map it down to, essentially, a math problem. Once we do that, we can explore a lot of different strategies and better understand how making small tweaks can help you defend against information leaks,” Deutsch says.

Surprising insights

They applied Metior in three case studies to compare attack strategies and analyze the information leakage from state-of-the-art obfuscation schemes. Through their evaluations, they saw how Metior can identify interesting behaviors that weren’t fully understood before.

For instance, a prior analysis determined that a certain type of side-channel attack, called probabilistic prime and probe, was successful because this sophisticated attack includes a preliminary step where it profiles a victim system to understand its defenses.

Using Metior, they show that this advanced attack actually works no better than a simple, generic attack and that it exploits different victim behaviors than researchers previously thought.   

Moving forward, the researchers want to continue enhancing Metior so the framework can analyze even very complicated obfuscation schemes in a more efficient manner. They also want to study additional obfuscation schemes and types of victim programs, as well as conduct more detailed analyses of the most popular defenses.

Ultimately, the researchers hope this work inspires others to study microarchitectural security evaluation methodologies that can be applied early in the chip design process.

“Any kind of microprocessor development is extraordinarily expensive and complicated, and design resources are extremely scarce. Having a way to evaluate the value of a security feature is extremely important before a company commits to microprocessor development. This is what Metior allows them to do in a very general way,” Emer says.

This research is funded, in part, by the National Science Foundation, the Air Force Office of Scientific Research, Intel, and the MIT RSC Research Fund.

###

Written by Adam Zewe, MIT News Office

Paper: “Metior: A Comprehensive Model for Evaluating Obfuscating Side-Channel Defense Schemes”

http://people.csail.mit.edu/emer/media/papers/2023.06.isca.metior.pdf

 

END



ELSE PRESS RELEASES FROM THIS DATE:

New pulsed laser deposition tool to predict superconductor failures tool purchase underwritten by U.S. Navy

New pulsed laser deposition tool to predict superconductor failures tool purchase underwritten by U.S. Navy
2023-06-28
A researcher at the Advanced Manufacturing Institute and the Texas Center for Superconductivity at the University of Houston (TCSUH) has found a way to reduce superconductor failures, enabled by a Pulsed Laser Deposition (PLD) tool. The popular thin film deposition instrument will be purchased with an $800,000 grant from the U.S. Office of Naval Research.   At extremely low temperatures (as low as cryogenic temperatures), superconductors allow electric current to flow without resistance and produce strong magnetic fields. That’s the principle behind Magnetic Resonance Imaging (MRI) ...

UCLA geologists are using artificial intelligence to predict landslides

2023-06-28
A new technique developed by UCLA geologists that uses artificial intelligence to better predict where and why landslides may occur could bolster efforts to protect lives and property in some of the world’s most disaster-prone areas. The new method, described in a paper published in the journal Communications Earth & Environment, improves the accuracy and interpretability of AI-based machine-learning techniques, requires far less computing power and is more broadly applicable than traditional predictive models. The approach would be particularly valuable in places like California, the researchers say, where drought, ...

BMI cutoffs for total shoulder arthroplasty increase health disparities by preventing those in need from undergoing surgery

BMI cutoffs for total shoulder arthroplasty increase health disparities by preventing those in need from undergoing surgery
2023-06-28
In June, the American Medical Association announced a new policy that encourages physicians not to focus solely on body mass index, or BMI, as a determinant of weight and health. As a ratio of an individual’s weight and height, BMI can provide an easy and inexpensive but often misleading measure of someone’s overall health.  While this new policy is not mandatory for physicians, it is part of a growing opinion that BMI is more useful for assessing population health rather than individual ...

Marine Corps Ph.D. graduate explores uncertainty in machine learning

Marine Corps Ph.D. graduate explores uncertainty in machine learning
2023-06-28
As battlespace sensors proliferate and data increases, commanders can easily find themselves in an information paradox: drowning in data, but starving for knowledge. U.S. Marine Corps Lt. Col. Pedro Ortiz, who graduated from the Naval Postgraduate School (NPS) on June 16 with a Ph.D. in Computer Science, focused his dissertation on this challenge to help enable rapid, effective decision-making for commanders in an era of ever-increasing sensor data and uncertainty. “I am very interested in applying artificial intelligence and machine learning to solve warfighter problems,” ...

New research from Portland State shows climate change will increase impacts of volcanic eruptions

2023-06-28
Volcanic disasters have been studied since Pompeii was buried in 79 A.D., leading the public to believe that scientists already know why, where, when and how long volcanoes will erupt. But Jonathan Fink, volcanologist and director of PSU’s Digital City Testbed Center, said these fundamental questions remain a mystery. Fink and Idowu "Jola" Ajibade, associate professor of Geography, recently published an article about how climate change will affect the societal impacts of eruptions. Their work is part of a novel 33-paper collection in the Bulletin of Volcanology, co-edited by Fink, which attempts to track how the entire field of volcanology has ...

World’s first glue derived from industrial bio-waste will make furniture recyclable

World’s first glue derived from industrial bio-waste will make furniture recyclable
2023-06-28
An innovative new adhesive, derived from purified and refined industrial bio-waste, should enable 90 percent of engineered wood products, such as furniture and construction boards, to become fully recyclable and helping to develop a sustainable circular economy in this sector. Currently, formaldehyde adhesives used by manufacturers, are toxic petrochemicals that are carcinogenic in nature. This prevents recycling and incineration meaning most construction panels and furniture made from engineered wood ends up in landfill. The new adhesive, derived from extracted and purified waste is ...

McMaster University team discovers hormonal pathway that increases calorie burning during weight loss

McMaster University team discovers hormonal pathway that increases calorie burning during weight loss
2023-06-28
Hamilton, ON (June 28, 2023) - Researchers led by McMaster University professor Gregory Steinberg and postdoctoral research fellow Dongdong Wang have uncovered a key mechanism for promoting weight loss and maintaining the burning of calories during dieting. The research team studied a hormone called GDF15 that they had previously shown to reduce appetite in response to the type 2 diabetes drug metformin. Their latest findings, published in Nature on June 28, showed that GDF15 also has the potential to help with weight loss. The research opens new possibilities to help people maintain weight loss ...

Cuttlefish camouflage: more than meets the eye

Cuttlefish camouflage: more than meets the eye
2023-06-28
Cuttlefish, along with other cephalopods like octopus and squid, are masters of disguise, changing their skin color and texture to blend in with their underwater surroundings.  Now, in a study published 28 June in Nature, researchers at the Okinawa Institute of Science and Technology (OIST) and the Max Planck Institute for Brain Research have shown that the way cuttlefish generate their camouflage pattern is much more complex than previously believed.  Cuttlefish create their dazzling skin patterns by precisely controlling millions of tiny skin pigment cells, ...

Outcomes of financial penalties to encourage hospital price transparency

2023-06-28
About The Study: Hospital compliance with federal price transparency regulations is high and increasing. The results of this study suggest that financial penalties may be a useful policy enforcement mechanism in health care. These findings are relevant for the enforcement of other regulations designed to promote transparency in health care.  Authors: Yunan Ji, Ph.D., of Georgetown University in Washington, D.C., is the corresponding author.   To access the embargoed study: Visit our For The Media website at this link ...

Brain volume changes in aging individuals with normal cognition

2023-06-28
About The Study: In this study of adults without dementia, age-dependent brain structure volumes and volume change rates in various brain structures were characterized using serial magnetic resonance imaging scans. These findings clarified the normal distributions in the aging brain, which are essential for understanding the process of age-related neurodegenerative diseases.  Authors: Shohei Fujita, M.D., Ph.D., of the University of Tokyo, is the corresponding author.   To access the embargoed study: Visit our For The Media website at this link https://media.jamanetwork.com/ (doi:10.1001/jamanetworkopen.2023.18153) Editor’s Note: Please ...

LAST 30 PRESS RELEASES:

High-risk pregnancy specialists analyze AI system to detect heart defects on fetal ultrasound exams

‘Altar tent’ discovery puts Islamic art at the heart of medieval Christianity

Policy briefs present approach for understanding prison violence

Early adult mortality is higher than expected in US post-COVID

Recycling lithium-ion batteries cuts emissions and strengthens supply chain

Study offers new hope for relieving chronic pain in dialysis patients

How does the atmosphere affect ocean weather?

Robots get smarter to work in sewers

Speech Accessibility Project data leads to recognition improvements on Microsoft Azure

Tigers in the neighborhood: How India makes room for both tigers and people

Grove School’s Arthur Paul Pedersen publishes critical essay on scientific measurement literacy

Moffitt study finds key biomarker to predict KRASG12C inhibitor effectiveness in lung cancer

Improving blood transfusion monitoring in critical care patients: Insights from diffuse optics

Powerful legal and financial services enable kleptocracy, research shows

Carbon capture from constructed wetlands declines as they age

UCLA-led study establishes link between early side effects from prostate cancer radiation and long-term side effects

Life cycles of some insects adapt well to a changing climate. Others, not so much.

With generative AI, MIT chemists quickly calculate 3D genomic structures

The gut-brain connection in Alzheimer’s unveiled with X-rays

NIH-funded clinical trial will evaluate new dengue therapeutic

Sound is a primary issue in the lives of skateboarders, study shows

Watch what you eat: NFL game advertisements promote foods high in fat, sodium

Red Dress Collection Concert hosted by Sharon Stone kicks off American Heart Month

One of the largest studies on preterm birth finds a maternal biomarker test significantly reduces neonatal morbidities and improves neonatal outcomes

One of the largest studies of its kind finds early intervention with iron delivered intravenously during pregnancy is a safe and effective treatment for anemia

New Case Western Reserve University study identifies key protein’s role in psoriasis

First-ever ethics checklist for portable MRI brain researchers

Addressing 3D effects of clouds for significant improvements of climate models

Gut microbes may mediate the link between drinking sugary beverages and diabetes risk

Ribosomes team up in difficult situations, new technology shows

[Press-News.org] MIT researchers devise a way to evaluate cybersecurity methods
The system analyzes the likelihood that an attacker could thwart a certain security scheme to steal secret information