Alenka G. Zajic

dblp:42/4332 · DBLP profile ↗
← Back
51ranked-venue papers
17as first author
6since 2021 · last 2023
0000-0003-1158-3785ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 16 · 4 since 2021Computer networks · 15 · 12 first-authorSecurity and privacy · 6 · 2 since 2021Software engineering, systems software and programming languages · 5Graphics, computer vision, multimedia, augmented reality and games · 2Theory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2023 MarCNNet: A Markovian Convolutional Neural Network for Malware Detection and Monitoring Multi-Core Systems
abstract
Leveraging side-channels enables zero-overhead detection of anomalies. These channels offer a non-instrumented program profiling capability by means of the distinct signatures generated by processing unintentional signals emitted during executions. In this paper, we propose a Markov based convolutional neural network (CNN) to monitor programs against anomalies on multi-core devices. We refer to the proposed framework as MarCNNet. In the model, the output of the CNN estimates the likelihood of the current state of the program, and the Markov Model tracks the process based on these estimates. If the estimates do not match the Markov model state diagram, it alerts anomaly, otherwise, it keeps monitoring. The framework also simplifies the training process because dependency among states is crucial for the Markov part of the model, but not for the CNN. Therefore, the neural network is trained by treating each state independent. However, for a test signal, both CNN and Markov parts of the framework are considered for malware detection to utilize the program flow. We tested the proposed model for various devices with different number of cores and threads of processes and demonstrated that the framework can detect malware with no false negatives, and a false positive rate less than 2%.
Baki Berkay Yilmaz, Frank Werner 0005, Sunjae Park, Elvan Mert Ugurlu, Erik J. Jorgensen, Milos Prvulovic, Alenka G. Zajic
IEEE Trans. Computers7
2022 PRIMER: Profiling Interrupts Using Electromagnetic Side-Channel for Embedded Devices
abstract
Recent proliferation of CPS and IoT devices has led to an increasing demand for analyzing performance and timing of event-driven computational activity, especially interrupts and exceptions. However, these devices typically lack hardware resources, power, and system-software infrastructure for profiling/monitoring such events. Even when feasible, the profiling/monitoring activity itself can perturb the performance and timing of the timing-sensitive activity to be analyzed, therefore producing misleading results. Thus, we present PRIMER, a novel approach for profiling interrupts. PRIMER leverages existing unintentional (side-channel) electromagnetic emanations of the profiled/monitored device to identify its asynchronous execution (e.g., interrupt handlers). PRIMER leaves the monitored system (and its behavior) completely unchanged, requires no system resources or support, and introduces neither overheads nor perturbation in the monitored system. We validate PRIMER by analyzing signals that correspond to five different types of interrupts on an IoT device (ARM Cortex-M), achieving 99.5% accuracy (with no false positives), and on an MSP430 microcontroller-based device with even better accuracy. We also demonstrate the effectiveness of PRIMER in analyzing page faults and network interrupts when executing real-world applications on a more sophisticated embedded device (ARM Cortex-A8), and show that the results provided by PRIMER can provide useful insights about an application's interaction with the system's virtual memory and network-oriented services.
Moumita Dey, Baki Berkay Yilmaz, Milos Prvulovic, Alenka G. Zajic
IEEE Trans. Computers4
2022 PITEM: Permutations-Based Instruction Tracking Via Electromagnetic Side-Channel Signal Analysis
abstract
The emergence of cyber-physical systems (CPS) and internet of things (IoT) devices impose significant security and privacy concerns that necessitate robust monitoring and malware detection systems. This paper proposes PITEM, a framework for instruction-level monitoring and malware detection using electromagnetic (EM) side-channels. PITEM identifiesinstruction typeswith similar EM emanations using hierarchical clustering. To track all combinations of theseinstruction types, we generate EM signatures for all permutations of them. In testing, we predict the permutation class of testing traces by a matched-filter-like predictor. We test the performance on two devices (FPGA-based and ARM-based) with 50 MHz and 1 GHz clock frequencies. We achieve 95.67 and 87.35 percent accuracies for these devices for single execution of permutations. We note that the accuracy increases to 100 percent when permutation blocks are repeated. Furthermore, we test the limits of the system by tracking permutations of instructions of the same type. With sufficient bandwidth and number of repetitions, individual instructions can be resolved with 87.5 and 95.78 percent accuracies for these devices. The performance is evaluated for different relative signal-to-noise ratio (SNR) levels and performance is stable for relative SNR values$>15$>15dB. Finally, we demonstrate PITEM's ability to detectfine-grainedmalware with 99.89 percent accuracy.
Elvan Mert Ugurlu, Baki Berkay Yilmaz, Alenka G. Zajic, Milos Prvulovic
IEEE Trans. Computers3
2022 Detection of Recycled ICs Using Backscattering Side-Channel Analysis
abstract
This article proposes a new, nondestructive method for detecting recycled integrated circuits (ICs) using the backscattering side-channel analysis (BSCA). In particular, this article explains the impact that aging has on the backscattering side-channel signal and validates the findings through simulations. Then, a new detection algorithm based on singular value decomposition for distinguishing unaged and aged ICs from their backscattered measurements is presented. The proposed method is then validated in a series of experiments. The results show that the proposed method is effective in detecting recycled ICs after being aged for a small fraction of the IC’s lifetime (roughly 66 days). The experiments also demonstrate the impact that circuit size and complexity have on detection accuracy.
Frank Werner 0005, Milos Prvulovic, Alenka G. Zajic
IEEE Trans. Very Large Scale Integr. Syst.3
2021 Nonce@Once: A Single-Trace EM Side Channel Attack on Several Constant-Time Elliptic Curve Implementations in Mobile Platforms
abstract
We present the first side-channel attack on full-fledged smartphones that recovers the elliptic curve secret scalar from the electromagnetic signal that corresponds to a single scalar-by-point multiplication in current versions of Libgcrypt, OpenSSL, HACL* and curve25519-donna. To avoid leaking information via side channels, these implementations follow the recommendations of RFC 7748 and use a constant-time conditional swap operation. Our attack targets signal differences created by systematic changes in operand values during this conditional swap operation. We deploy the attack, using low-cost equipment (<$800), against two Android-based mobile phones and against a Linux-based IoT development board. We repeat the attack 100 times, each time with a different scalar, on each device. In all of the implementations considered in this work, our attack successfully recovers the full secret key within seconds. To mitigate the attack we suggest randomizing the exclusive-or mask in the conditional swap operation. We show that this countermeasure is effective in preventing this and similar attacks.
Monjur Alam, Baki Berkay Yilmaz, Frank Werner 0005, Niels Samwel, Alenka G. Zajic, Daniel Genkin, Yuval Yarom, Milos Prvulovic
EuroS&P5
2021 IDEA: Intrusion Detection through Electromagnetic-Signal Analysis for Critical Embedded and Cyber-Physical Systems
abstract
We propose a novel framework called IDEA that exploits electromagnetic (EM) side-channel signals to detect malicious activity on embedded and cyber-physical systems (CPS). IDEA first records EM emanations from an uncompromised reference device to establish a baseline of reference EM patterns. IDEA then monitors the target device's EM emanations. When the observed EM emanations deviate from the reference patterns, IDEA reports this as an anomalous or malicious activity. IDEA does not require any resource or infrastructure on, or any modification to, the monitored system itself. In fact, IDEA is isolated from the target device, and monitors the device without any physical contact. We evaluate IDEA by monitoring the target device while it is executing embedded applications with malicious code injections such as Distributed Denial of Service (DDoS), Ransomware and code modification. We further implement a control-flow hijack attack, an advanced persistent threat, and a firmware modification on three CPSs: an embedded medical device called SyringePump, an industrial Proportional-Integral-Derivative (PID) Controller, and a Robotic Arm, using a popular embedded system, Arduino UNO. The results demonstrate that IDEA can detect different attacks with excellent accuracy (AUC > 99.5%, and 100 percent detection with less than 1 percent false positives) from distances up to 3 m.
Haider Adnan Khan, Nader Sehatbakhsh, Luong N. Nguyen, Robert Locke Callan, Arie Yeredor, Milos Prvulovic, Alenka G. Zajic
IEEE Trans. Dependable Secur. Comput.7
2020 EMSim: A Microarchitecture-Level Simulation Tool for Modeling Electromagnetic Side-Channel Signals
abstract
Side-channel attacks have become a serious security concern for computing systems, especially for embedded devices, where the device is often located in, or in proximity to, a public place, and yet the system contains sensitive information. To design systems that are highly resilient to such attacks, an accurate and efficient design-stage quantitative analysis of side-channel leakage is needed. For many systems properties (e.g., performance, power, etc.), cycle-accurate simulation can provide such an efficient-yet-accurate design-stage estimate. Unfortunately, for an important class of side-channels, electromagnetic emanations, such a model does not exist, and there has not even been much quantitative evidence about what level of modeling detail (e.g., hardware, microarchitecture, etc.) would be needed for high accuracy. This paper presents EMSim, an approach that enables simulation of the electromagnetic (EM) side-channel signals cycle-by-cycle using a detailed micro-architectural model of the device. To evaluate EMSim, we compare its signals against actual EM signals emanated from real hardware (FPGA-based RISC-V processor), and find that they match very closely. To gain further insights, we also experimentally identify how the accuracy of the simulation degrades when key microarchitectural features (e.g., pipeline stall, cache-miss, etc.) and other hardware behaviors (e.g., data-dependent switching activity) are omitted from the simulation model. We further evaluate how robust the simulation-based results are, by comparing them to real signals collected in different conditions (manufacturing, distance, etc.). Finally, to show the applicability of EMSim, we demonstrate how it can be used to measure side-channel leakage through simulation at design-stage.
Nader Sehatbakhsh, Baki Berkay Yilmaz, Alenka G. Zajic, Milos Prvulovic
HPCA3
2020 A New Side-Channel Vulnerability on Modern Computers by Exploiting Electromagnetic Emanations from the Power Management Unit
abstract
This paper presents a new micro-architectural vulnerability on the power management units of modern computers which creates an electromagnetic-based side-channel. The key observations that enable us to discover this sidechannel are: 1) in an effort to manage and minimize power consumption, modern microprocessors have a number of possible operating modes (power states) in which various sub-systems of the processor are powered down, 2) for some of the transitions between power states, the processor also changes the operating mode of the voltage regulator module (VRM) that supplies power to the affected sub-system, and 3) the electromagnetic (EM) emanations from the VRM are heavily dependent on its operating mode. As a result, these state-dependent EM emanations create a side-channel which can potentially reveal sensitive information about the current state of the processor and, more importantly, the programs currently being executed. To demonstrate the feasibility of exploiting this vulnerability, we create a covert channel by utilizing the changes in the processor's power states. We show how such a covert channel can be leveraged to exfiltrate sensitive information from a secured and completely isolated (air-gapped) laptop system by placing a compact, inexpensive receiver in proximity to that system. To further show the severity of this attack, we also demonstrate how such a covert channel can be established when the target and the receiver are several meters away from each other, including scenarios where the receiver and the target are separated by a wall. Compared to the state-of-the-art, the proposed covert channel has >3x higher bit-rate. Finally, to demonstrate that this new vulnerability is not limited to being used as a covert channel, we demonstrate how it can be used for attacks such as keystroke logging.
Nader Sehatbakhsh, Baki Berkay Yilmaz, Alenka G. Zajic, Milos Prvulovic
HPCA3
2020 Cell-Phone Classification: A Convolutional Neural Network Approach Exploiting Electromagnetic Emanations
abstract
In this paper, we propose a methodology to identify both the brand of a cell-phone, and the status of its camera by exploiting electromagnetic (EM) emanations. The method is composed of two parts: Feature extraction and Convolutional Neural Network (CNN). We first extract features by averaging magnitudes of short-time Fourier transform (STFT) of the measured EM signal, which helps to reduce input dimension of the neural network, and to filter spurious emissions. The extracted features are fed into the proposed CNN, which contains two convolutional layers (followed by max-pooling layers), and four fully-connected layers. Finally, we provide experimental results which exhibit more than 99% classification accuracy for the test signals.
Baki Berkay Yilmaz, Elvan Mert Ugurlu, Alenka G. Zajic, Milos Prvulovic
ICASSP3
2020 REMOTE: Robust External Malware Detection Framework by Using Electromagnetic Signals
abstract
Cyber-physical systems (CPS) are controlling many critical and sensitive aspects of our physical world while being continuously exposed to potential cyber-attacks. These systems typically have limited performance, memory, and energy reserves, which limits their ability to run existing advanced malware protection, and that, in turn, makes securing them very challenging. To tackle these problems, this paper proposes, REMOTE, a new robust framework to detect malware by externally observing Electromagnetic (EM) signals emitted by an electronic computing device (e.g., a microprocessor) while running a known application, in real-time and with a low detection latency, and without any a priori knowledge of the malware. REMOTE does not require any resources or infrastructure on, or any modifications to, the monitored system itself, which makes REMOTE especially suitable for malware detection on resource-constrained devices such as embedded devices, CPSs, and Internet of Things (IoT) devices where hardware and energy resources may be limited. To demonstrate the usability of REMOTE in real-world scenarios, we port two real-world programs (an embedded medical device and an industrial PID controller), each with a meaningful attack (a code-reuse and a code-injection attack), to four different hardware platforms. We also port shellcode-based DDoS and Ransomware attacks to five different standard applications on an embedded system. To further demonstrate the applicability of REMOTE to commercial CPS, we use REMOTE to monitor a Robotic Arm. Our results on all these different hardware platforms show that, for all attacks on each of the platforms, REMOTE successfully detects each instance of an attack and has99.9 percent true positive rates) under all these conditions. We also compare REMOTE to prior work EDDIE [1] and SYNDROME [2], and demonstrate that these prior work are unable to achieve high accuracy under these variations.
Nader Sehatbakhsh, Alireza Nazari, Monjur Alam, Frank Werner 0005, Yuanda Zhu, Alenka G. Zajic, Milos Prvulovic
IEEE Trans. Computers6
2020 Electromagnetic Side Channel Information Leakage Created by Execution of Series of Instructions in a Computer Processor
abstract
The side-channel leakage is a consequence of program execution in a computer processor, and understanding relationship between code execution and information leakage is a necessary step in estimating information leakage and its capacity limits. This paper proposes a methodology to relate program execution to electromagnetic side-channel emanations and estimates side-channel information capacity created by execution of series of instructions (e.g., a function, a procedure, or a program) in a processor. To model dependence among program instructions in a code, we propose to use Markov source model, which includes the dependencies among sequence of instructions as well as dependencies among instructions as they pass through a pipeline of the processor. The emitted electromagnetic (EM) signals during instruction executions are natural choice for the inputs into the model. To obtain the channel inputs for the proposed model, we derive a mathematical relationship between the emanated instruction signal power (ESP) and total emanated signal power while running a program. Then, we derive the leakage capacity of EM side channels created by execution of series of instructions in a processor. Finally, we provide experimental results to demonstrate that leakages could be severe and that a dedicated attacker could obtain important information.
Baki Berkay Yilmaz, Milos Prvulovic, Alenka G. Zajic
IEEE Trans. Inf. Forensics Secur.3
2020 Communication Model and Capacity Limits of Covert Channels Created by Software Activities
abstract
It has been shown that digital and/or analog characteristics of electronic devices during executing programs can create a side-channel which an attacker can exploit to extract sensitive information such as cryptographic keys. When the attacker modifies the software application to exfiltrate sensitive information through a channel, this channel is called a covert channel. In this paper, we model this covert channel as a communication channel and derive upper and lower capacity bounds. Because the covert channels are not designed to transmit information, they are exposed not only to the errors created by the transmission, but also by varying the execution time of computer activities, and/or by insertions from other activities such as interrupts, stalls, etc. Combining all of these effects, we propose to model the covert channel as an insertion channel where the transmitted sequence is a pulse amplitude modulated signal with random pulse positions. Utilizing this model, we derive capacity bounds of the covert channel with random insertion and substitution due to the noise and jitter errors, and propose a receiver design that can correctly detect the computer-activity-created signals. To illustrate the severity of leakages, we perform experiments with high clock speed devices at some distance. Further, the theoretical derivations are compared to empirical results, and show good agreement.
Baki Berkay Yilmaz, Nader Sehatbakhsh, Alenka G. Zajic, Milos Prvulovic
IEEE Trans. Inf. Forensics Secur.3
2020 Modeling of 300 GHz Chip-to-Chip Wireless Channels in Metal Enclosures
abstract
This paper proposes a two dimensional (2-D) statistical channel model for Terahertz (THz) chip-to-chip wireless communication in desktop size metal enclosures. This model differs from traditional statistical channel models as it models both traveling and resonant waves that exist inside metal enclosures. Based on the cavity environment and the statistical properties of the channel inside the metal cavity, the geometrical model which describes propagation in resonant cavity as a superposition of LoS, single bounced (SB), double bounced (DB), and multi-bounced (MB) rays is proposed. Based on the geometrical model, a parametric reference model is proposed. Furthermore, the path loss model that captures signal strength variation in a resonant cavity is proposed. Frequency correlation functions (FCF) and power delay profiles (PDP) for different possible chip-to-chip communication scenarios are derived and compared with the measured ones. The results show a good agreement between the simulated and measured statistics.
Jinbang Fu, Prateek Juyal, Alenka G. Zajic
IEEE Trans. Wirel. Commun.3
2019 Zero-overhead path prediction with progressive symbolic execution
abstract
In previous work, we introduced zero-overhead profiling (ZOP), a technique that leverages the electromagnetic emissions generated by the computer hardware to profile a program without instrumenting it. Although effective, ZOP has several shortcomings: it requires test inputs that achieve extensive code coverage for its training phase; it predicts path profiles instead of complete execution traces; and its predictions can suffer unrecoverable accuracy losses. In this paper, we present zero-overhead path prediction (ZOP-2), an approach that extends ZOP and addresses its limitations. First, ZOP-2 achieves high coverage during training through progressive symbolic execution (PSE)-symbolic execution of increasingly small program fragments. Second, ZOP-2 predicts complete execution traces, rather than path profiles. Finally, ZOP-2 mitigates the problem of path mispredictions by using a stateless approach that can recover from prediction errors. We evaluated our approach on a set of benchmarks with promising results; for the cases considered, (1) ZOP-2 achieved over 90% path prediction accuracy, and (2) PSE covered feasible paths missed by traditional symbolic execution, thus boosting ZOP-2's accuracy.
Richard Rutledge, Sunjae Park, Haider Adnan Khan, Alessandro Orso, Milos Prvulovic, Alenka G. Zajic
ICSE6
2019 EMMA: Hardware/Software Attestation Framework for Embedded Systems Using Electromagnetic Signals
abstract
Establishing trust for an execution environment is an important problem, and practical solutions for it rely on attestation, where an untrusted system (prover) computes a response to a challenge sent by the trusted system (verifier). The response typically is a checksum of the prover's program, which the verifier checks against expected values for a "clean" (trustworthy) system. The main challenge in attestation is that, in addition to checking the response, the verifier also needs to verify the integrity of the response computation. On higher-end processors, this integrity is verified cryptographically, using dedicated trusted hardware. On embedded systems, however, constraints prevent the use of such hardware support. Instead, a popular approach is to use the request-to-response time as a way to establish confidence. However, the overall request-to-response time provides only one coarse-grained measurement from which the integrity of the attestation is to be inferred, and even that is noisy because it includes the network latency and/or variations due to micro-architectural events. Thus, the attestation is vulnerable to attacks where the adversary has tampered with response computation, but the resulting additional computation time is small relative to the overall request-to-response time.
Nader Sehatbakhsh, Alireza Nazari, Haider Adnan Khan, Alenka G. Zajic, Milos Prvulovic
MICRO4
2019 Creating a Backscattering Side Channel to Enable Detection of Dormant Hardware Trojans
abstract
This paper describes a new physical side channel, i.e., the backscattering side channel, created by transmitting a signal toward the integrated circuits (ICs), where the internal impedance changes caused by on-chip switching activity modulate the signal that is backscattered (reflected) from the IC. To demonstrate how this new side channel can be used to detect small changes in circuit impedances, we propose a new method for nondestructively detecting hardware Trojans (HTs) from outside the chip. We experimentally confirm, using measurements on one physical instance for training and nine other physical instances for testing, that the new side channel, when combined with an HT detection method, allows detection of a dormant HT in 100% of the HT-afflicted measurements for a number of different HTs while producing no false positives in HT-free measurements. Furthermore, additional experiments are conducted to compare the backscattering-based detection to one that uses the traditional EM-emanation-based side channel. These results show that backscattering-based detection outperforms the EM side channel, confirm that dormant HTs are much more difficult for detection than HTs that have been activated, and show how detection is affected by changing the HT's size and physical location on the IC.
Luong N. Nguyen, Chia-Lin Cheng, Milos Prvulovic, Alenka G. Zajic
IEEE Trans. Very Large Scale Integr. Syst.4
2018 Modelling Jitter in Wireless Channel Created by Processor-Memory Activity
abstract
A wireless communication created by a computer software activity is described and modelled. The generation of this communication link is a consequence of electromagnetic (EM) emanations emitted during computer activity. This wireless channel in addition to channel errors due to noise, also experiences jitter created by the software activity “transmitter” which lacks precise synchronization. Also, the “transmitter” gets interrupted with other (system) activity, and the transmitted signal goes through a channel obstructed by metal, plastic, etc. To capture all these effects, we have modelled transmitted sequence as a pulse amplitude modulated (PAM) signal with random varying pulse position. From the model, we have derived the power spectral density and the bit error rate of the transmitted signal and presented performance analysis of such a channel.
Baki Berkay Yilmaz, Alenka G. Zajic, Milos Prvulovic
ICASSP2
2018 EMPROF: Memory Profiling Via EM-Emanation in IoT and Hand-Held Devices
abstract
This paper presents EMPROF, a new method for profiling the performance impact of the memory subsystem without any support on, or interference with, the profiled system. Rather than rely on hardware support and/or software instrumentation on the profiled system, EMPROF analyzes the system's EM emanations to identify processor stalls that are associated with last-level cache (LLC) misses. This enables EMPROF to accurately pinpoint LLC misses in the execution timeline and to measure the cost (stall time) of each miss. Since EMPROF has zero "observer effect", so it can be used to profile applications that adjust their activity to their performance. It has no overhead on target machine, so it can be used for profiling embedded, hand-held, and IoT devices which usually have limited support for collecting, and limited resources for storing, the profiling data. Finally, since EMPROF can profile the system as-is, its profiling of boot code and other hard-to-profile software components is as accurate as its profiling of application code. To illustrate the effectiveness of EMPROF, we first validate its results using microbenchmarks with known memory behavior, and also on SPEC benchmarks running a cycle-accurate simulator that can provide detailed ground-truth data about LLC misses and processor stalls. We then demonstrate the effectiveness of EMPROF on real systems, including profiling of boot activity, show how its results can be attributed to the specific parts of the application code when that code is available, and provide additional insight on the statistics reported by EMPROF and how they are affected by the EM signal bandwidth provided to EMPROF.
Moumita Dey, Alireza Nazari, Alenka G. Zajic, Milos Prvulovic
MICRO3
2018 Characterization of 300 GHz Wireless Channels for Rack-to-Rack Communications in Data Centers
abstract
This paper presents characterization of 300 GHz channel with optical lenses for wireless rack-to-rack data center communications. Measurements are conducted in line-of-sight (LoS), obstructed-LoS (OLoS), reflected-non-LoS (RNLoS), and obstructed-RNLoS (ORNLoS) scenarios, which evaluate the impact of obstructions such as cables on THz propagation as well as possibility of using existing metal objects as reflectors that guide waves for non-LoS type of links that are prevalent in data centers. Since optical lenses are needed to extend the communication range beyond 1m, we have evaluated path loss in such an environment and estimated path loss model parameters. The results indicate that optical lenses create a waveguide-like environment with PLEs of 1.54 in the LoS link and 1.36 in the RNLoS link. Multiple reflections are observed in PDPs when lenses are used to extend the distance but they decay as the distance increases. Additionally, reflector in the RNLoS link preserves multiple reflections longer than traditional LoS link and thus limit the coherence bandwidth Bc. Finally, when obstructions are present, the ORNLoS link has lower pathloss at distance beyond 130 cm and has less multipath compared to the OLoS link. If obstructions caused by cables are unavoidable, ORNLoS link performs better than OLoS link.
Chia-Lin Cheng, Alenka G. Zajic
PIMRC2
2018 One&Done: A Single-Decryption EM-Based Attack on OpenSSL's Constant-Time Blinded RSA
Monjur Alam, Haider Adnan Khan, Moumita Dey, Nishith Sinha, Robert Locke Callan, Alenka G. Zajic, Milos Prvulovic
USENIX Security Symposium6
2018 Capacity of the EM Covert/Side-Channel Created by the Execution of Instructions in a Processor
abstract
The goal of this paper is to answer how much information is “transmitted” by the execution of particular sequence of instructions in a processor. Introducing such a measure would provide quantitative guidance for designing programs and computer hardware that minimizes inadvertent (side channel) information leakage, and would also help detect parts of a program or hardware design that have unusually high leakage (i.e., were designed to function as covert channel “transmitters”). To answer this question, we propose a new method to estimate the maximum information leakage through EM signals generated by the execution of instructions in a processor. We start by deriving a mathematical relationship between electromagnetic side-channel energy of individual instructions and the measured pairwise side-channel signal power. Then, we use this measure to calculate the transition probabilities needed for estimating capacity. Finally, we propose a new method to estimate side/covert channel capacity created by the execution of instructions in a processor and illustrate our results in several computer systems.
Baki Berkay Yilmaz, Robert Locke Callan, Milos Prvulovic, Alenka G. Zajic
IEEE Trans. Inf. Forensics Secur.4
2017 EDDIE: EM-Based Detection of Deviations in Program Execution
abstract
This paper describes EM-Based Detection of Deviations in Program Execution (EDDIE), a new method for detecting anomalies in program execution, such as malware and other code injections, without introducing any overheads, adding any hardware support, changing any software, or using any resources on the monitored system itself. Monitoring with EDDIE involves receiving electromagnetic (EM) emanations that are emitted as a side effect of execution on the monitored system, and it relies on spikes in the EM spectrum that are produced as a result of periodic (e.g. loop) activity in the monitored execution. During training, EDDIE characterizes normal execution behavior in terms of peaks in the EM spectrum that are observed at various points in the program execution, but it does not need any characterization of the malware or other code that might later be injected. During monitoring, EDDIE identifies peaks in the observed EM spectrum, and compares these peaks to those learned during training. Since EDDIE requires no resources on the monitored machine and no changes to the monitored software, it is especially well suited for security monitoring of embedded and IoT devices. We evaluate EDDIE on a real IoT system and in a cycle-accurate simulator, and find that even relatively brief injected bursts of activity (a few milliseconds) are detected by EDDIE with high accuracy, and that it also accurately detects when even a few instructions are injected into an existing loop within the application.
Alireza Nazari, Nader Sehatbakhsh, Monjur Alam, Alenka G. Zajic, Milos Prvulovic
ISCA4
2017 Methods for Channel Sounder Measurement Verification
abstract
We describe an activity of the 5G mmWave Channel Sounder Alliance to verify the hardware performance of channel sounders operating at mmWave frequencies. Such verification procedures are critical when attempting to compare data from sounders having different architectures in various environments. Two different methods are described and illustrated with simple measurement examples.
Kate A. Remley, Camillo Gentile, Alenka G. Zajic, Jeanne T. Quimby
VTC Fall3
2016 Zero-overhead profiling via EM emanations
abstract
This paper presents an approach for zero-overhead profiling (ZOP). ZOP accomplishes accurate program profiling with no modification to the program or system during profiling and no dedicated hardware features. To do so, ZOP records the electromagnetic (EM) emanations generated by computing systems during program execution and analyzes the recorded emanations to track a program’s execution path and generate profiling information. Our approach consists of two main phases. In the training phase, ZOP instruments the program and runs it against a set of inputs to collect path timing information while simultaneously collecting waveforms for the EM emanations generated by the program. In the profiling phase, ZOP runs the original (i.e., uninstrumented and unmodified) program against inputs whose executions need to be profiled, records the waveforms produced by the program, and matches these waveforms with those collected during training to predict which parts of the code were exercised by the inputs and how often. We evaluated an implementation of ZOP on several benchmarks and our results show that ZOP can predict path profiling information for these benchmarks with greater than 94% accuracy on average.
Robert Locke Callan, Farnaz Behrang, Alenka G. Zajic, Milos Prvulovic, Alessandro Orso
ISSTA3
2016 Spectral profiling: Observer-effect-free profiling by monitoring EM emanations
abstract
This paper presents Spectral Profiling, a new method for profiling program execution without instrumenting or otherwise affecting the profiled system. Spectral Profiling monitors EM emanations unintentionally produced by the profiled system, looking for spectral “spikes” produced by periodic program activity (e.g. loops). This allows Spectral Profiling to determine which parts of the program have executed at what time. By analyzing the frequency and shape of the spectral “spike”, Spectral Profiling can obtain additional information such as the per-iteration execution time of a loop. The key advantage of Spectral Profiling is that it can monitor a system as-is, without program instrumentation, system activity, etc. associated with the profiling itself, i.e. it completely eliminates the “Observer's Effect” and allows profiling of programs whose execution is performance-dependent and/or programs that run on even the simplest embedded systems that have no resources or support for profiling. We evaluate the effectiveness of Spectral Profiling by applying it to several benchmarks from MiBench suite on a real system, and also on a cycle-accurate simulator. Our results confirm that Spectral Profiling yields useful information about the runtime behavior of a program, allowing Spectral Profiling to be used for profiling in systems where profiling infrastructure is not available, or where profiling overheads may perturb the results too much (“Observer's Effect”).
Nader Sehatbakhsh, Alireza Nazari, Alenka G. Zajic, Milos Prvulovic
MICRO3
2016 Statistical Modeling and Simulation of Short-Range Device-to-Device Communication Channels at Sub-THz Frequencies
abstract
A 2-D geometrical propagation model for short-range device-to-device desktop communication channels at sub-terahertz (sub-THz) frequencies is proposed. Based on the geometrical model, a parametric reference model for short-range sub-THz multipath fading channels is developed. From the reference model, the corresponding frequency correlation function and the power delay profile (PDP) are derived and compared with the measured data. The results show good agreement between the measured and theoretical PDPs. Finally, a new sum-of-sinusoids-based simulation model for wideband sub-THz channels is proposed. The statistics of the reference model are verified by simulation. The results show that the simulation model is a good approximation of the reference model.
Alenka G. Zajic
IEEE Trans. Wirel. Commun.2
2015 FASE: finding amplitude-modulated side-channel emanations
abstract
While all computation generates electromagnetic (EM) side-channel signals, some of the strongest and farthest-propagating signals are created when an existing strong periodic signal (e.g. a clock signal) becomes stronger or weaker (amplitude-modulated) depending on processor or memory activity. However, modern systems create emanations at thousands of different frequencies, so it is a difficult, error-prone, and time-consuming task to find those few emanations that are AM-modulated by processor/memory activity.
Robert Locke Callan, Alenka G. Zajic, Milos Prvulovic
ISCA2
2014 A Practical Methodology for Measuring the Side-Channel Signal Available to the Attacker for Instruction-Level Events
abstract
This paper presents a new metric, which we call Signal Available to Attacker (SAVAT), that measures the side channel signal created by a specific single-instruction difference in program execution, i.e. The amount of signal made available to a potential attacker who wishes to decide whether the program has executed instruction/event A or instruction/event B. We also devise a practical methodology for measuring SAVAT in real systems using only user-level access permissions and common measurement equipment. Finally, we perform a case study where we measure electromagnetic (EM) emanations SAVAT among 11 different instructions for three different laptop systems. Our findings from these experiments confirm key intuitive expectations, e.g. That SAVAT between on-chip instructions and off-chip memory accesses tends to be higher than between two on-chip instructions. However, we find that particular instructions, such as integer divide, have much higher SAVAT than other instructions in the same general category (integer arithmetic), and that last-level-cache hits and misses have similar (high) SAVAT. Overall, we confirm that our new metric and methodology can help discover the most vulnerable aspects of a processor architecture or a program, and thus inform decision-making about how to best manage the overall side channel vulnerability of a processor, a program, or a system.
Robert Locke Callan, Alenka G. Zajic, Milos Prvulovic
MICRO2
2014 Experimental Verification of the Non-Stationary Statistical Model for V2V Scatter Channels
abstract
This paper compares our non-stationary geometric- stochastic channel model for vehicle-to-vehicle scatter channels with measurement data collected in a vehicle-to-vehicle measurement campaign. The measurements were conducted on a forest road near Munich at 5.2 GHz using a car mounted transmitter and receiver platform. The data is evaluated in terms of delay and Doppler frequency and then compared to a scaled version of the joint delay Doppler probability density function. The close agreement between the analytical and empirical data confirms the utility of our non-stationary geometric stochastic model.
Michael Walter 0002, Uwe-Carsten Fiebig, Alenka G. Zajic
VTC Fall3
2013 Traffic steering between a low-latency unswitched TL ring and a high-throughput switched on-chip interconnect
abstract
Growth in core count creates an increasing demand for interconnect bandwidth, driving a change from shared buses to packet-switched on-chip interconnects. However, this increases the latency between cores separated by many links and switches. In this paper, we show that a low-latency unswitched interconnect built with transmission lines can be synergistically used with a high-throughput switched interconnect. First, we design a broadcast ring as a chain of unidirectional transmission line structures with very low latency but limited throughput. Then, we create a new adaptive packet steering policy that judiciously uses the limited throughput of this ring by balancing expected latency benefit and ring utilization. Although the ring uses 1.3% of the on-chip metal area, our experimental results show that, in combination with our steering, it provides an execution time reduction of 12.4% over a mesh-only baseline.
Jungju Oh, Alenka G. Zajic, Milos Prvulovic
PACT2
2013 Envelope level crossing rate in mobile-to-mobile underwater fading channels
abstract
An analytical model for mobile-to-mobile underwater communications is presented. From the analytical model, the envelope level crossing rate is derived for a non-isotropic scattering environment. The obtained analytical results are compared with measured data. The close agreement between the analytical and empirical curves confirms the utility of the proposed model.
Bryan Blankenagel, Alenka G. Zajic
ICC2
2013 Simulation Model for Wideband Mobile-to-Mobile Underwater Fading Channels
abstract
This paper presents a two-dimensional (2-D) reference model for wideband mobile-to-mobile (M-to-M) underwater fading channels. From the reference model, the timefrequency correlation function for a 2-D non-isotropic scattering environment is derived. Finally, the sum-of-sinusoids simulator is presented and shown to closely match the statistical properties of the reference model.
Bryan Blankenagel, Alenka G. Zajic
VTC Spring2
2011 TLSync: support for multiple fast barriers using on-chip transmission lines
abstract
As the number of cores on a single-chip grows, scalable barrier synchronization becomes increasingly difficult to implement. In software implementations, such as the tournament barrier, a larger number of cores results in a longer latency for each round and a larger number of rounds. Hardware barrier implementations require significant dedicated wiring, e.g., using a reduction (arrival) tree and a notification (release) tree, and multiple instances of this wiring are needed to support multiple barriers (e.g., when concurrently executing multiple parallel applications).
Jungju Oh, Milos Prvulovic, Alenka G. Zajic
ISCA3
2011 Estimation of Velocities in Mobile-to-Mobile Wireless Fading Channels
abstract
This paper proposes a new crossing-rate-based estimator that jointly estimates velocities of both the transmitter and receiver in mobile-to-mobile communications (M-to-M). The proposed estimator is designed for narrow-band wireless M-to-M communications over noise-free isotropic fading channels. The proposed estimator is evaluated through extensive computer simulations and the results show that the proposed algorithm provides very good estimation accuracy. Furthermore, the proposed estimator is tested in the presence of a non-isotropic scattering, line-of-sight propagation, and Gaussian noise and the results show that the good estimation accuracy is preserved.
Alenka G. Zajic
VTC Fall1
2010 Statistical Modeling of Underwater Wireless Channels
abstract
This paper proposes a geometry-based statistical model for multiple-input multiple-output shallow water wireless channels. From the reference model, the corresponding space-time-frequency correlation function and space-Doppler power spectral density are derived. To verify our results, the derived statistics are compared with the experimentally obtained channel statistics and close agreement is observed.
Alenka G. Zajic
GLOBECOM1
2009 Impact of Mutual Coupling on MIMO Vehicle-to-Vehicle Systems
abstract
This paper proposes a three-dimensional (3-D) model for wideband multiple-input multiple-output (MIMO) vehicle-to-vehicle (V-to-V) multipath fading channels that accounts for mutual coupling among both, transmit and receive antenna elements. From the 3-D model, the spatial correlation is derived for a 3-D non-isotropic scattering environment. Finally, this model is used to evaluate the effect of mutual coupling on the antenna element patterns, spatial correlation, and received power of MIMO V-to-V systems in urban environments.
Alenka G. Zajic
GLOBECOM1
2009 A space-time code design for CPM: diversity order and coding gain
abstract
Sufficient conditions are derived under which$M$-ary partial- and full-response continuous phase modulation (CPM) space–time (ST) codes will attain both full spatial diversity and optimal coding gain. General code construction rules are desirable due to the nonlinearity and inherent memory of the CPM signals which makes manual design or computer search difficult. Using a linear decomposition of CPM signals with tilted phase, we identify a rank criterion for$M$-ary partial- and full-response CPM that specifies the set of allowable modulation indices. We also propose a coding gain design criterion. Optimization of the coding gain for CPM ST codes is shown to depend on the CPM frequency/phase shaping pulse, modulation index, and codewords. The modulation indices and phase shaping functions that improve the coding gain are specified. Finally, optimization of coding gain for ST-CPM and orthogonal ST-CPM codewords is discussed.
Alenka G. Zajic, Gordon L. Stüber
IEEE Trans. Inf. Theory1
2009 Three-dimensional modeling and simulation of wideband MIMO mobile-to-mobile channels
abstract
A three-dimensional (3-D) geometrical propagation model for wideband multiple-input multiple-output (MIMO) mobile-to-mobile (M-to-M) communications is proposed. Based on the geometrical model, a 3-D parametric reference model for wideband MIMO M-to-M multipath fading channels is developed. From the reference model, the corresponding space-time-frequency correlation function is derived for a 3-D non-isotropic scattering environment. It is shown that the time and frequency dispersion of a wide sense stationary uncorrelated scattering channel cannot be treated independently, contrary to common practice. From the space-time-frequency correlation function, the space-Doppler power spectral density and the power space-delay spectrum are derived and compared with measured data. Finally, a new sum-of-sinusoids based simulation model for wideband MIMO M-to-M Ricean fading channels is proposed. The statistics of the simulation model are verified by simulation. The results show that the simulation model is a good approximation of the reference model.
Alenka G. Zajic, Gordon L. Stüber
IEEE Trans. Wirel. Commun.1
2008 Maximum Likelihood Method for MIMO Mobile-to-Mobile Channel Parameter Estimation
abstract
A three-dimensional reference model for wideband multiple-input multiple-output mobile-to-mobile channels is reviewed. To allow comparison between the proposed model and measured data, a new maximum likelihood based stochastic estimator is derived. The proposed estimator extracts the relevant model parameters from the measured data. The performance of the new estimator is evaluated by deriving the Cramer-Rao lower bound (CRLB) and by comparing the mean square error of the parameter estimates to the CRLB. Simulation results show that the proposed estimator has an asymptotically optimal performance, since it reaches the CRLB for a small number of samples.
Alenka G. Zajic, Gordon L. Stüber
GLOBECOM1
2008 Envelope Level Crossing Rate and Average Fade Duration in Mobile-To-Mobile Fading Channels
abstract
A three-dimensional (3-D) analytical model for mobile-to-mobile communications is presented. From the analytical model, the envelope level crossing rate and average fade duration are derived for a 3-D non-isotropic scattering environment. The obtained analytical results are compared with measured data. The close agreement between the analytical and empirical curves confirms the utility of the proposed model.
Alenka G. Zajic, Gordon L. Stüber, Thomas G. Pratt
ICC1
2008 Statistical modeling and experimental verification of wideband MIMO mobile-to-mobile channels in highway environments
abstract
A three-dimensional reference model for wideband multiple-input multiple-output (MIMO) mobile-to-mobile (M-to-M) channels is reviewed. To validate the reference model, an experimental MIMO M-to-M channel-sounding campaign was conducted for M-to-M vehicular communication with vehicles travelling along expressways in a metropolitan area. The measured data is processed and the channel statistics obtained from the reference model and from the empirical measurements are compared. The close agreement between the analytically and empirically obtained channel statistics confirms the utility of the proposed reference model.
Alenka G. Zajic, Gordon L. Stüber, Thomas G. Pratt
PIMRC1
2008 Performance Analysis of a System using Coordinate Interleaving and Constellation Rotation in Rayleigh Fading Channels
abstract
Diversity can play an important role in the performance improvement of a communication system in fading channels. The achievable performance with signal space diversity (SSD) is analyzed and a closed form expression for the upper bound of average probability of bit error (Pb) for M-ary phase shift keying (MPSK) in Rayleigh fading channel is presented. The problem of calculating Pbof coherent MPSK over a Rayleigh fading channel has been studied previously in the literature. A solution based on the nearest neighbors was given. In this paper we show that the results with the nearest neighbor approximation represent an expurgated bound and are only valid for a small range of rotational angles. Exact pair-wise error probability (PEP) is derived for Rayleigh fading channels. It is shown that Gray signal constellation mapping is not necessarily the best option for a system employing coordinate interleaving and constellation rotation. Rotation angles are optimized by finding the minimum of the upper bound of Pb. It is shown that the new derived bound is tight for the entire range of rotational angles at high signal-to-noise ratio. Furthermore, the performance of the system in case of phase estimation error is also investigated by simulations.
Nauman F. Kiyani, Jos H. Weber, Alenka G. Zajic, Gordon L. Stüber
VTC Fall3
2008 Statistical Properties of Wideband MIMO Mobile-to-Mobile Channels (Special Paper)
abstract
A three-dimensional (3-D) theoretical model for wideband multiple-input multiple-output (MIMO) mobile-to- mobile (M-to-M) channels is presented. Based on this model, the statistical properties of wideband MIMO M-to-M channels are derived. In particular, the space-time-frequency correlation function, the power space-delay spectral density, and the envelope level crossing rate are derived for a 3-D non-isotropic scattering environment. Finally, to validate the theoretical derivations, some simulation results are presented and compared with measured data.
Alenka G. Zajic, Gordon L. Stüber
WCNC1
2007 A Three Dimensional Parametric Model for Wideband MIMO Mobile-to-Mobile Channels
abstract
A three-dimensional (3-D) geometrical propagation model for wideband multiple-input multiple-output (MIMO) mobile-to-mobile (M-to-M) communications is proposed. Based on the geometrical model, a 3-D parametric reference model for wideband MIMO M-to-M multipath fading channels is developed. From the reference model, the space-time-frequency correlation function and the space-Doppler power spectral density are derived for a 3-D non-isotropic scattering environment. Finally, some simulation results are presented and compared with measured data. The close agreement between the theoretical and empirical curves confirms the utility of the proposed wideband model.
Alenka G. Zajic, Gordon L. Stüber
GLOBECOM1
2007 A Space-Time Code Design for Partial-Response CPM: Diversity Order and Coding Gain
abstract
Using a linear decomposition of continuous phase modulated (CPM) signals with tilted-phase, sufficient conditions are derived under whichM-ary partial-response CPM space-time codes will attain both full spatial diversity and optimal coding gain. A rank criterion forM-ary partial-response CPM that specifies the set of allowable modulation indices is identified. Furthermore, optimization of the coding gain for CPM space-time codes is shown to depend on the CPM frequency/phase shaping pulse, modulation index, and codewords. The modulation indices and phase shaping functions that optimize the coding gain are specified. Finally, optimization of CPM space-time codewords is discussed.
Alenka G. Zajic, Gordon L. Stüber
ICC1
2007 Influence of 3-D Spatial Correlation on the Capacity of MIMO Mobile-to-Mobile Channels
abstract
A three-dimensional (3-D) theoretical model for MIMO mobile-to-mobile (M-to-M) multipath fading channels is proposed and its spatial correlation function is derived. This correlation function is used to evaluate the effect of spatial correlation on the capacity of uniform linear antenna arrays. The effects of antenna spacing and antenna orientations on capacity are studied.
Alenka G. Zajic, Gordon L. Stüber
VTC Spring1
2007 A Three-Dimensional MIMO Mobile-to-Mobile Channel Model
abstract
A three-dimensional (3-D) geometrical propagation model for multi-input-multi-output (MIMO) mobile-to-mobile (M-to-M) communications is proposed. Based on the geometrical model, a 3-D reference model for MIMO M-to-M multipath fading channels is proposed. From the reference model, a closed-form joint space-time correlation function is derived for a 3-D non-isotropic scattering environment and it is show that many existing correlation functions are special cases of the derived space-time correlation function.
Alenka G. Zajic, Gordon L. Stüber
WCNC1
2006 Optimization of Coding Gain for Full-Response CPM Space-Time Codes
abstract
Conditions are derived under which M-ary full-response CPM space-time codes will attain full spatial diversity and optimal coding gain. General code construction rules are desirable due to the nonlinearity and inherent memory of CPM signals which make manual design or computer search difficult. Optimization of the coding gain for CPM space-time codes is shown to depend on the CPM frequency/phase shaping pulse, modulation index, and codewords. The modulation indices and phase shaping functions that optimize the coding gain are specified. Finally, optimization of ST-CPM codewords is discussed.
Alenka G. Zajic, Gordon L. Stüber
GLOBECOM1
2006 Space-Time Correlated MIMO Mobile-To-Mobile Channels
abstract
A theoretical model is proposed for multi-input-multi-output (MIMO) mobile-to-mobile (M-to-M) Rayleigh fading channels, such that the complex faded envelope does not depend on the distance between scatterers and antenna elements. From this model, a closed-form joint space-time correlation function is derived for 2-D non-isotropic scattering environment. Also, a space-frequency power density spectrum of the complex faded envelope is derived, assuming 2-D isotropic scattering environment. Finally, a statistical simulation model for MIMO M-to-M Rayleigh fading channels is proposed. The space-time correlation function of the simulation model is derived and verified by simulation, and an adaptive method for choosing the number of scatterers in simulations is proposed. The results show that the statistical simulation model is a good approximation of the theoretical model
Alenka G. Zajic, Gordon L. Stüber
PIMRC1
2006 A new simulation model for mobile-to-mobile Rayleigh fading channels
abstract
A new statistical sum-of-sinusoids simulation model is proposed for mobile-to-mobile Rayleigh fading channels and compared with existing simulation models. The new proposed model has a lower variance of the auto-correlation functions, i.e., it converges faster and has a lower correlation between the in-phase and quadrature components of the complex faded envelope than existing simulation models. This model yields adequate statistics with only 30 simulation runs
Alenka G. Zajic, Gordon L. Stüber
WCNC1
2006 Efficient simulation of rayleigh fading with enhanced de-correlation properties
abstract
New sum-of-sinusoids simulation models are proposed for Rayleigh fading channels and compared with existing simulation models. First, an ergodic statistical ("deterministic") model is proposed that, compared to existing models, yields a significantly lower cross-correlation between different complex envelopes and between the quadrature components of each complex envelope. However, the auto-correlation functions of the quadrature components still do not match the theoretical functions. To overcome this disadvantage, we also propose a new statistical simulator that converges faster than existing statistical models, and has lower cross-correlations between different complex envelopes and between the quadrature components of each complex envelope. This new statistical model yields adequate statistics with only 30 simulation runs
Alenka G. Zajic, Gordon L. Stüber
IEEE Trans. Wirel. Commun.1