EDBT 2026 Demo / reviewers in the wild / expert
Alenka G. Zajic
dblp:42/4332
· DBLP profile ↗
51ranked-venue papers
17as first author
6since 2021 · last 2023
0000-0003-1158-3785ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 16 · 4 since 2021Computer networks · 15 · 12 first-authorSecurity and privacy · 6 · 2 since 2021Software engineering, systems software and programming languages · 5Graphics, computer vision, multimedia, augmented reality and games · 2Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | MarCNNet: A Markovian Convolutional Neural Network for Malware Detection and Monitoring Multi-Core SystemsabstractLeveraging side-channels enables zero-overhead detection of anomalies. These channels offer a non-instrumented program profiling capability by means of the distinct signatures generated by processing unintentional signals emitted during executions. In this paper, we propose a Markov based convolutional neural network (CNN) to monitor programs against anomalies on multi-core devices. We refer to the proposed framework as MarCNNet. In the model, the output of the CNN estimates the likelihood of the current state of the program, and the Markov Model tracks the process based on these estimates. If the estimates do not match the Markov model state diagram, it alerts anomaly, otherwise, it keeps monitoring. The framework also simplifies the training process because dependency among states is crucial for the Markov part of the model, but not for the CNN. Therefore, the neural network is trained by treating each state independent. However, for a test signal, both CNN and Markov parts of the framework are considered for malware detection to utilize the program flow. We tested the proposed model for various devices with different number of cores and threads of processes and demonstrated that the framework can detect malware with no false negatives, and a false positive rate less than 2%. Baki Berkay Yilmaz, Frank Werner 0005, Sunjae Park, Elvan Mert Ugurlu, Erik J. Jorgensen, Milos Prvulovic, Alenka G. Zajic |
IEEE Trans. Computers | 7 |
| 2022 | PRIMER: Profiling Interrupts Using Electromagnetic Side-Channel for Embedded DevicesabstractRecent proliferation of CPS and IoT devices has led to an increasing demand for analyzing performance and timing of event-driven computational activity, especially interrupts and exceptions. However, these devices typically lack hardware resources, power, and system-software infrastructure for profiling/monitoring such events. Even when feasible, the profiling/monitoring activity itself can perturb the performance and timing of the timing-sensitive activity to be analyzed, therefore producing misleading results. Thus, we present PRIMER, a novel approach for profiling interrupts. PRIMER leverages existing unintentional (side-channel) electromagnetic emanations of the profiled/monitored device to identify its asynchronous execution (e.g., interrupt handlers). PRIMER leaves the monitored system (and its behavior) completely unchanged, requires no system resources or support, and introduces neither overheads nor perturbation in the monitored system. We validate PRIMER by analyzing signals that correspond to five different types of interrupts on an IoT device (ARM Cortex-M), achieving 99.5% accuracy (with no false positives), and on an MSP430 microcontroller-based device with even better accuracy. We also demonstrate the effectiveness of PRIMER in analyzing page faults and network interrupts when executing real-world applications on a more sophisticated embedded device (ARM Cortex-A8), and show that the results provided by PRIMER can provide useful insights about an application's interaction with the system's virtual memory and network-oriented services. Moumita Dey, Baki Berkay Yilmaz, Milos Prvulovic, Alenka G. Zajic |
IEEE Trans. Computers | 4 |
| 2022 | PITEM: Permutations-Based Instruction Tracking Via Electromagnetic Side-Channel Signal AnalysisabstractThe emergence of cyber-physical systems (CPS) and internet of things (IoT) devices impose significant security and privacy concerns that necessitate robust monitoring and malware detection systems. This paper proposes PITEM, a framework for instruction-level monitoring and malware detection using electromagnetic (EM) side-channels. PITEM identifiesinstruction typeswith similar EM emanations using hierarchical clustering. To track all combinations of theseinstruction types, we generate EM signatures for all permutations of them. In testing, we predict the permutation class of testing traces by a matched-filter-like predictor. We test the performance on two devices (FPGA-based and ARM-based) with 50 MHz and 1 GHz clock frequencies. We achieve 95.67 and 87.35 percent accuracies for these devices for single execution of permutations. We note that the accuracy increases to 100 percent when permutation blocks are repeated. Furthermore, we test the limits of the system by tracking permutations of instructions of the same type. With sufficient bandwidth and number of repetitions, individual instructions can be resolved with 87.5 and 95.78 percent accuracies for these devices. The performance is evaluated for different relative signal-to-noise ratio (SNR) levels and performance is stable for relative SNR values$>15$>15dB. Finally, we demonstrate PITEM's ability to detectfine-grainedmalware with 99.89 percent accuracy. Elvan Mert Ugurlu, Baki Berkay Yilmaz, Alenka G. Zajic, Milos Prvulovic |
IEEE Trans. Computers | 3 |
| 2022 | Detection of Recycled ICs Using Backscattering Side-Channel AnalysisabstractThis article proposes a new, nondestructive method for detecting recycled integrated circuits (ICs) using the backscattering side-channel analysis (BSCA). In particular, this article explains the impact that aging has on the backscattering side-channel signal and validates the findings through simulations. Then, a new detection algorithm based on singular value decomposition for distinguishing unaged and aged ICs from their backscattered measurements is presented. The proposed method is then validated in a series of experiments. The results show that the proposed method is effective in detecting recycled ICs after being aged for a small fraction of the IC’s lifetime (roughly 66 days). The experiments also demonstrate the impact that circuit size and complexity have on detection accuracy. Frank Werner 0005, Milos Prvulovic, Alenka G. Zajic |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2021 | Nonce@Once: A Single-Trace EM Side Channel Attack on Several Constant-Time Elliptic Curve Implementations in Mobile PlatformsabstractWe present the first side-channel attack on full-fledged smartphones that recovers the elliptic curve secret scalar from the electromagnetic signal that corresponds to a single scalar-by-point multiplication in current versions of Libgcrypt, OpenSSL, HACL* and curve25519-donna. To avoid leaking information via side channels, these implementations follow the recommendations of RFC 7748 and use a constant-time conditional swap operation. Our attack targets signal differences created by systematic changes in operand values during this conditional swap operation. We deploy the attack, using low-cost equipment (<$800), against two Android-based mobile phones and against a Linux-based IoT development board. We repeat the attack 100 times, each time with a different scalar, on each device. In all of the implementations considered in this work, our attack successfully recovers the full secret key within seconds. To mitigate the attack we suggest randomizing the exclusive-or mask in the conditional swap operation. We show that this countermeasure is effective in preventing this and similar attacks. Monjur Alam, Baki Berkay Yilmaz, Frank Werner 0005, Niels Samwel, Alenka G. Zajic, Daniel Genkin, Yuval Yarom, Milos Prvulovic |
EuroS&P | 5 |
| 2021 | IDEA: Intrusion Detection through Electromagnetic-Signal Analysis for Critical Embedded and Cyber-Physical SystemsabstractWe propose a novel framework called IDEA that exploits electromagnetic (EM) side-channel signals to detect malicious activity on embedded and cyber-physical systems (CPS). IDEA first records EM emanations from an uncompromised reference device to establish a baseline of reference EM patterns. IDEA then monitors the target device's EM emanations. When the observed EM emanations deviate from the reference patterns, IDEA reports this as an anomalous or malicious activity. IDEA does not require any resource or infrastructure on, or any modification to, the monitored system itself. In fact, IDEA is isolated from the target device, and monitors the device without any physical contact. We evaluate IDEA by monitoring the target device while it is executing embedded applications with malicious code injections such as Distributed Denial of Service (DDoS), Ransomware and code modification. We further implement a control-flow hijack attack, an advanced persistent threat, and a firmware modification on three CPSs: an embedded medical device called SyringePump, an industrial Proportional-Integral-Derivative (PID) Controller, and a Robotic Arm, using a popular embedded system, Arduino UNO. The results demonstrate that IDEA can detect different attacks with excellent accuracy (AUC > 99.5%, and 100 percent detection with less than 1 percent false positives) from distances up to 3 m. Haider Adnan Khan, Nader Sehatbakhsh, Luong N. Nguyen, Robert Locke Callan, Arie Yeredor, Milos Prvulovic, Alenka G. Zajic |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2020 | EMSim: A Microarchitecture-Level Simulation Tool for Modeling Electromagnetic Side-Channel SignalsabstractSide-channel attacks have become a serious security concern for computing systems, especially for embedded devices, where the device is often located in, or in proximity to, a public place, and yet the system contains sensitive information. To design systems that are highly resilient to such attacks, an accurate and efficient design-stage quantitative analysis of side-channel leakage is needed. For many systems properties (e.g., performance, power, etc.), cycle-accurate simulation can provide such an efficient-yet-accurate design-stage estimate. Unfortunately, for an important class of side-channels, electromagnetic emanations, such a model does not exist, and there has not even been much quantitative evidence about what level of modeling detail (e.g., hardware, microarchitecture, etc.) would be needed for high accuracy. This paper presents EMSim, an approach that enables simulation of the electromagnetic (EM) side-channel signals cycle-by-cycle using a detailed micro-architectural model of the device. To evaluate EMSim, we compare its signals against actual EM signals emanated from real hardware (FPGA-based RISC-V processor), and find that they match very closely. To gain further insights, we also experimentally identify how the accuracy of the simulation degrades when key microarchitectural features (e.g., pipeline stall, cache-miss, etc.) and other hardware behaviors (e.g., data-dependent switching activity) are omitted from the simulation model. We further evaluate how robust the simulation-based results are, by comparing them to real signals collected in different conditions (manufacturing, distance, etc.). Finally, to show the applicability of EMSim, we demonstrate how it can be used to measure side-channel leakage through simulation at design-stage. Nader Sehatbakhsh, Baki Berkay Yilmaz, Alenka G. Zajic, Milos Prvulovic |
HPCA | 3 |
| 2020 | A New Side-Channel Vulnerability on Modern Computers by Exploiting Electromagnetic Emanations from the Power Management UnitabstractThis paper presents a new micro-architectural vulnerability on the power management units of modern computers which creates an electromagnetic-based side-channel. The key observations that enable us to discover this sidechannel are: 1) in an effort to manage and minimize power consumption, modern microprocessors have a number of possible operating modes (power states) in which various sub-systems of the processor are powered down, 2) for some of the transitions between power states, the processor also changes the operating mode of the voltage regulator module (VRM) that supplies power to the affected sub-system, and 3) the electromagnetic (EM) emanations from the VRM are heavily dependent on its operating mode. As a result, these state-dependent EM emanations create a side-channel which can potentially reveal sensitive information about the current state of the processor and, more importantly, the programs currently being executed. To demonstrate the feasibility of exploiting this vulnerability, we create a covert channel by utilizing the changes in the processor's power states. We show how such a covert channel can be leveraged to exfiltrate sensitive information from a secured and completely isolated (air-gapped) laptop system by placing a compact, inexpensive receiver in proximity to that system. To further show the severity of this attack, we also demonstrate how such a covert channel can be established when the target and the receiver are several meters away from each other, including scenarios where the receiver and the target are separated by a wall. Compared to the state-of-the-art, the proposed covert channel has >3x higher bit-rate. Finally, to demonstrate that this new vulnerability is not limited to being used as a covert channel, we demonstrate how it can be used for attacks such as keystroke logging. Nader Sehatbakhsh, Baki Berkay Yilmaz, Alenka G. Zajic, Milos Prvulovic |
HPCA | 3 |
| 2020 | Cell-Phone Classification: A Convolutional Neural Network Approach Exploiting Electromagnetic EmanationsabstractIn this paper, we propose a methodology to identify both the brand of a cell-phone, and the status of its camera by exploiting electromagnetic (EM) emanations. The method is composed of two parts: Feature extraction and Convolutional Neural Network (CNN). We first extract features by averaging magnitudes of short-time Fourier transform (STFT) of the measured EM signal, which helps to reduce input dimension of the neural network, and to filter spurious emissions. The extracted features are fed into the proposed CNN, which contains two convolutional layers (followed by max-pooling layers), and four fully-connected layers. Finally, we provide experimental results which exhibit more than 99% classification accuracy for the test signals. Baki Berkay Yilmaz, Elvan Mert Ugurlu, Alenka G. Zajic, Milos Prvulovic |
ICASSP | 3 |
| 2020 | REMOTE: Robust External Malware Detection Framework by Using Electromagnetic SignalsabstractCyber-physical systems (CPS) are controlling many critical and sensitive aspects of our physical world while being continuously exposed to potential cyber-attacks. These systems typically have limited performance, memory, and energy reserves, which limits their ability to run existing advanced malware protection, and that, in turn, makes securing them very challenging. To tackle these problems, this paper proposes, REMOTE, a new robust framework to detect malware by externally observing Electromagnetic (EM) signals emitted by an electronic computing device (e.g., a microprocessor) while running a known application, in real-time and with a low detection latency, and without any a priori knowledge of the malware. REMOTE does not require any resources or infrastructure on, or any modifications to, the monitored system itself, which makes REMOTE especially suitable for malware detection on resource-constrained devices such as embedded devices, CPSs, and Internet of Things (IoT) devices where hardware and energy resources may be limited. To demonstrate the usability of REMOTE in real-world scenarios, we port two real-world programs (an embedded medical device and an industrial PID controller), each with a meaningful attack (a code-reuse and a code-injection attack), to four different hardware platforms. We also port shellcode-based DDoS and Ransomware attacks to five different standard applications on an embedded system. To further demonstrate the applicability of REMOTE to commercial CPS, we use REMOTE to monitor a Robotic Arm. Our results on all these different hardware platforms show that, for all attacks on each of the platforms, REMOTE successfully detects each instance of an attack and has99.9 percent true positive rates) under all these conditions. We also compare REMOTE to prior work EDDIE [1] and SYNDROME [2], and demonstrate that these prior work are unable to achieve high accuracy under these variations. Nader Sehatbakhsh, Alireza Nazari, Monjur Alam, Frank Werner 0005, Yuanda Zhu, Alenka G. Zajic, Milos Prvulovic |
IEEE Trans. Computers | 6 |
| 2020 | Electromagnetic Side Channel Information Leakage Created by Execution of Series of Instructions in a Computer ProcessorabstractThe side-channel leakage is a consequence of program execution in a computer processor, and understanding relationship between code execution and information leakage is a necessary step in estimating information leakage and its capacity limits. This paper proposes a methodology to relate program execution to electromagnetic side-channel emanations and estimates side-channel information capacity created by execution of series of instructions (e.g., a function, a procedure, or a program) in a processor. To model dependence among program instructions in a code, we propose to use Markov source model, which includes the dependencies among sequence of instructions as well as dependencies among instructions as they pass through a pipeline of the processor. The emitted electromagnetic (EM) signals during instruction executions are natural choice for the inputs into the model. To obtain the channel inputs for the proposed model, we derive a mathematical relationship between the emanated instruction signal power (ESP) and total emanated signal power while running a program. Then, we derive the leakage capacity of EM side channels created by execution of series of instructions in a processor. Finally, we provide experimental results to demonstrate that leakages could be severe and that a dedicated attacker could obtain important information. Baki Berkay Yilmaz, Milos Prvulovic, Alenka G. Zajic |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | Communication Model and Capacity Limits of Covert Channels Created by Software ActivitiesabstractIt has been shown that digital and/or analog characteristics of electronic devices during executing programs can create a side-channel which an attacker can exploit to extract sensitive information such as cryptographic keys. When the attacker modifies the software application to exfiltrate sensitive information through a channel, this channel is called a covert channel. In this paper, we model this covert channel as a communication channel and derive upper and lower capacity bounds. Because the covert channels are not designed to transmit information, they are exposed not only to the errors created by the transmission, but also by varying the execution time of computer activities, and/or by insertions from other activities such as interrupts, stalls, etc. Combining all of these effects, we propose to model the covert channel as an insertion channel where the transmitted sequence is a pulse amplitude modulated signal with random pulse positions. Utilizing this model, we derive capacity bounds of the covert channel with random insertion and substitution due to the noise and jitter errors, and propose a receiver design that can correctly detect the computer-activity-created signals. To illustrate the severity of leakages, we perform experiments with high clock speed devices at some distance. Further, the theoretical derivations are compared to empirical results, and show good agreement. Baki Berkay Yilmaz, Nader Sehatbakhsh, Alenka G. Zajic, Milos Prvulovic |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | Modeling of 300 GHz Chip-to-Chip Wireless Channels in Metal EnclosuresabstractThis paper proposes a two dimensional (2-D) statistical channel model for Terahertz (THz) chip-to-chip wireless communication in desktop size metal enclosures. This model differs from traditional statistical channel models as it models both traveling and resonant waves that exist inside metal enclosures. Based on the cavity environment and the statistical properties of the channel inside the metal cavity, the geometrical model which describes propagation in resonant cavity as a superposition of LoS, single bounced (SB), double bounced (DB), and multi-bounced (MB) rays is proposed. Based on the geometrical model, a parametric reference model is proposed. Furthermore, the path loss model that captures signal strength variation in a resonant cavity is proposed. Frequency correlation functions (FCF) and power delay profiles (PDP) for different possible chip-to-chip communication scenarios are derived and compared with the measured ones. The results show a good agreement between the simulated and measured statistics. Jinbang Fu, Prateek Juyal, Alenka G. Zajic |
IEEE Trans. Wirel. Commun. | 3 |
| 2019 | Zero-overhead path prediction with progressive symbolic executionabstractIn previous work, we introduced zero-overhead profiling (ZOP), a technique that leverages the electromagnetic emissions generated by the computer hardware to profile a program without instrumenting it. Although effective, ZOP has several shortcomings: it requires test inputs that achieve extensive code coverage for its training phase; it predicts path profiles instead of complete execution traces; and its predictions can suffer unrecoverable accuracy losses. In this paper, we present zero-overhead path prediction (ZOP-2), an approach that extends ZOP and addresses its limitations. First, ZOP-2 achieves high coverage during training through progressive symbolic execution (PSE)-symbolic execution of increasingly small program fragments. Second, ZOP-2 predicts complete execution traces, rather than path profiles. Finally, ZOP-2 mitigates the problem of path mispredictions by using a stateless approach that can recover from prediction errors. We evaluated our approach on a set of benchmarks with promising results; for the cases considered, (1) ZOP-2 achieved over 90% path prediction accuracy, and (2) PSE covered feasible paths missed by traditional symbolic execution, thus boosting ZOP-2's accuracy. Richard Rutledge, Sunjae Park, Haider Adnan Khan, Alessandro Orso, Milos Prvulovic, Alenka G. Zajic |
ICSE | 6 |
| 2019 | EMMA: Hardware/Software Attestation Framework for Embedded Systems Using Electromagnetic SignalsabstractEstablishing trust for an execution environment is an important problem, and practical solutions for it rely on attestation, where an untrusted system (prover) computes a response to a challenge sent by the trusted system (verifier). The response typically is a checksum of the prover's program, which the verifier checks against expected values for a "clean" (trustworthy) system. The main challenge in attestation is that, in addition to checking the response, the verifier also needs to verify the integrity of the response computation. On higher-end processors, this integrity is verified cryptographically, using dedicated trusted hardware. On embedded systems, however, constraints prevent the use of such hardware support. Instead, a popular approach is to use the request-to-response time as a way to establish confidence. However, the overall request-to-response time provides only one coarse-grained measurement from which the integrity of the attestation is to be inferred, and even that is noisy because it includes the network latency and/or variations due to micro-architectural events. Thus, the attestation is vulnerable to attacks where the adversary has tampered with response computation, but the resulting additional computation time is small relative to the overall request-to-response time. Nader Sehatbakhsh, Alireza Nazari, Haider Adnan Khan, Alenka G. Zajic, Milos Prvulovic |
MICRO | 4 |
| 2019 | Creating a Backscattering Side Channel to Enable Detection of Dormant Hardware TrojansabstractThis paper describes a new physical side channel, i.e., the backscattering side channel, created by transmitting a signal toward the integrated circuits (ICs), where the internal impedance changes caused by on-chip switching activity modulate the signal that is backscattered (reflected) from the IC. To demonstrate how this new side channel can be used to detect small changes in circuit impedances, we propose a new method for nondestructively detecting hardware Trojans (HTs) from outside the chip. We experimentally confirm, using measurements on one physical instance for training and nine other physical instances for testing, that the new side channel, when combined with an HT detection method, allows detection of a dormant HT in 100% of the HT-afflicted measurements for a number of different HTs while producing no false positives in HT-free measurements. Furthermore, additional experiments are conducted to compare the backscattering-based detection to one that uses the traditional EM-emanation-based side channel. These results show that backscattering-based detection outperforms the EM side channel, confirm that dormant HTs are much more difficult for detection than HTs that have been activated, and show how detection is affected by changing the HT's size and physical location on the IC. Luong N. Nguyen, Chia-Lin Cheng, Milos Prvulovic, Alenka G. Zajic |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2018 | Modelling Jitter in Wireless Channel Created by Processor-Memory ActivityabstractA wireless communication created by a computer software activity is described and modelled. The generation of this communication link is a consequence of electromagnetic (EM) emanations emitted during computer activity. This wireless channel in addition to channel errors due to noise, also experiences jitter created by the software activity “transmitter” which lacks precise synchronization. Also, the “transmitter” gets interrupted with other (system) activity, and the transmitted signal goes through a channel obstructed by metal, plastic, etc. To capture all these effects, we have modelled transmitted sequence as a pulse amplitude modulated (PAM) signal with random varying pulse position. From the model, we have derived the power spectral density and the bit error rate of the transmitted signal and presented performance analysis of such a channel. Baki Berkay Yilmaz, Alenka G. Zajic, Milos Prvulovic |
ICASSP | 2 |
| 2018 | EMPROF: Memory Profiling Via EM-Emanation in IoT and Hand-Held DevicesabstractThis paper presents EMPROF, a new method for profiling the performance impact of the memory subsystem without any support on, or interference with, the profiled system. Rather than rely on hardware support and/or software instrumentation on the profiled system, EMPROF analyzes the system's EM emanations to identify processor stalls that are associated with last-level cache (LLC) misses. This enables EMPROF to accurately pinpoint LLC misses in the execution timeline and to measure the cost (stall time) of each miss. Since EMPROF has zero "observer effect", so it can be used to profile applications that adjust their activity to their performance. It has no overhead on target machine, so it can be used for profiling embedded, hand-held, and IoT devices which usually have limited support for collecting, and limited resources for storing, the profiling data. Finally, since EMPROF can profile the system as-is, its profiling of boot code and other hard-to-profile software components is as accurate as its profiling of application code. To illustrate the effectiveness of EMPROF, we first validate its results using microbenchmarks with known memory behavior, and also on SPEC benchmarks running a cycle-accurate simulator that can provide detailed ground-truth data about LLC misses and processor stalls. We then demonstrate the effectiveness of EMPROF on real systems, including profiling of boot activity, show how its results can be attributed to the specific parts of the application code when that code is available, and provide additional insight on the statistics reported by EMPROF and how they are affected by the EM signal bandwidth provided to EMPROF. Moumita Dey, Alireza Nazari, Alenka G. Zajic, Milos Prvulovic |
MICRO | 3 |
| 2018 | Characterization of 300 GHz Wireless Channels for Rack-to-Rack Communications in Data CentersabstractThis paper presents characterization of 300 GHz channel with optical lenses for wireless rack-to-rack data center communications. Measurements are conducted in line-of-sight (LoS), obstructed-LoS (OLoS), reflected-non-LoS (RNLoS), and obstructed-RNLoS (ORNLoS) scenarios, which evaluate the impact of obstructions such as cables on THz propagation as well as possibility of using existing metal objects as reflectors that guide waves for non-LoS type of links that are prevalent in data centers. Since optical lenses are needed to extend the communication range beyond 1m, we have evaluated path loss in such an environment and estimated path loss model parameters. The results indicate that optical lenses create a waveguide-like environment with PLEs of 1.54 in the LoS link and 1.36 in the RNLoS link. Multiple reflections are observed in PDPs when lenses are used to extend the distance but they decay as the distance increases. Additionally, reflector in the RNLoS link preserves multiple reflections longer than traditional LoS link and thus limit the coherence bandwidth Bc. Finally, when obstructions are present, the ORNLoS link has lower pathloss at distance beyond 130 cm and has less multipath compared to the OLoS link. If obstructions caused by cables are unavoidable, ORNLoS link performs better than OLoS link. Chia-Lin Cheng, Alenka G. Zajic |
PIMRC | 2 |
| 2018 | One&Done: A Single-Decryption EM-Based Attack on OpenSSL's Constant-Time Blinded RSA
Monjur Alam, Haider Adnan Khan, Moumita Dey, Nishith Sinha, Robert Locke Callan, Alenka G. Zajic, Milos Prvulovic |
USENIX Security Symposium | 6 |
| 2018 | Capacity of the EM Covert/Side-Channel Created by the Execution of Instructions in a ProcessorabstractThe goal of this paper is to answer how much information is “transmitted” by the execution of particular sequence of instructions in a processor. Introducing such a measure would provide quantitative guidance for designing programs and computer hardware that minimizes inadvertent (side channel) information leakage, and would also help detect parts of a program or hardware design that have unusually high leakage (i.e., were designed to function as covert channel “transmitters”). To answer this question, we propose a new method to estimate the maximum information leakage through EM signals generated by the execution of instructions in a processor. We start by deriving a mathematical relationship between electromagnetic side-channel energy of individual instructions and the measured pairwise side-channel signal power. Then, we use this measure to calculate the transition probabilities needed for estimating capacity. Finally, we propose a new method to estimate side/covert channel capacity created by the execution of instructions in a processor and illustrate our results in several computer systems. Baki Berkay Yilmaz, Robert Locke Callan, Milos Prvulovic, Alenka G. Zajic |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2017 | EDDIE: EM-Based Detection of Deviations in Program ExecutionabstractThis paper describes EM-Based Detection of Deviations in Program Execution (EDDIE), a new method for detecting anomalies in program execution, such as malware and other code injections, without introducing any overheads, adding any hardware support, changing any software, or using any resources on the monitored system itself. Monitoring with EDDIE involves receiving electromagnetic (EM) emanations that are emitted as a side effect of execution on the monitored system, and it relies on spikes in the EM spectrum that are produced as a result of periodic (e.g. loop) activity in the monitored execution. During training, EDDIE characterizes normal execution behavior in terms of peaks in the EM spectrum that are observed at various points in the program execution, but it does not need any characterization of the malware or other code that might later be injected. During monitoring, EDDIE identifies peaks in the observed EM spectrum, and compares these peaks to those learned during training. Since EDDIE requires no resources on the monitored machine and no changes to the monitored software, it is especially well suited for security monitoring of embedded and IoT devices. We evaluate EDDIE on a real IoT system and in a cycle-accurate simulator, and find that even relatively brief injected bursts of activity (a few milliseconds) are detected by EDDIE with high accuracy, and that it also accurately detects when even a few instructions are injected into an existing loop within the application. Alireza Nazari, Nader Sehatbakhsh, Monjur Alam, Alenka G. Zajic, Milos Prvulovic |
ISCA | 4 |
| 2017 | Methods for Channel Sounder Measurement VerificationabstractWe describe an activity of the 5G mmWave Channel Sounder Alliance to verify the hardware performance of channel sounders operating at mmWave frequencies. Such verification procedures are critical when attempting to compare data from sounders having different architectures in various environments. Two different methods are described and illustrated with simple measurement examples. Kate A. Remley, Camillo Gentile, Alenka G. Zajic, Jeanne T. Quimby |
VTC Fall | 3 |
| 2016 | Zero-overhead profiling via EM emanationsabstractThis paper presents an approach for zero-overhead profiling (ZOP). ZOP accomplishes accurate program profiling with no modification to the program or system during profiling and no dedicated hardware features. To do so, ZOP records the electromagnetic (EM) emanations generated by computing systems during program execution and analyzes the recorded emanations to track a program’s execution path and generate profiling information. Our approach consists of two main phases. In the training phase, ZOP instruments the program and runs it against a set of inputs to collect path timing information while simultaneously collecting waveforms for the EM emanations generated by the program. In the profiling phase, ZOP runs the original (i.e., uninstrumented and unmodified) program against inputs whose executions need to be profiled, records the waveforms produced by the program, and matches these waveforms with those collected during training to predict which parts of the code were exercised by the inputs and how often. We evaluated an implementation of ZOP on several benchmarks and our results show that ZOP can predict path profiling information for these benchmarks with greater than 94% accuracy on average. Robert Locke Callan, Farnaz Behrang, Alenka G. Zajic, Milos Prvulovic, Alessandro Orso |
ISSTA | 3 |
| 2016 | Spectral profiling: Observer-effect-free profiling by monitoring EM emanationsabstractThis paper presents Spectral Profiling, a new method for profiling program execution without instrumenting or otherwise affecting the profiled system. Spectral Profiling monitors EM emanations unintentionally produced by the profiled system, looking for spectral “spikes” produced by periodic program activity (e.g. loops). This allows Spectral Profiling to determine which parts of the program have executed at what time. By analyzing the frequency and shape of the spectral “spike”, Spectral Profiling can obtain additional information such as the per-iteration execution time of a loop. The key advantage of Spectral Profiling is that it can monitor a system as-is, without program instrumentation, system activity, etc. associated with the profiling itself, i.e. it completely eliminates the “Observer's Effect” and allows profiling of programs whose execution is performance-dependent and/or programs that run on even the simplest embedded systems that have no resources or support for profiling. We evaluate the effectiveness of Spectral Profiling by applying it to several benchmarks from MiBench suite on a real system, and also on a cycle-accurate simulator. Our results confirm that Spectral Profiling yields useful information about the runtime behavior of a program, allowing Spectral Profiling to be used for profiling in systems where profiling infrastructure is not available, or where profiling overheads may perturb the results too much (“Observer's Effect”). Nader Sehatbakhsh, Alireza Nazari, Alenka G. Zajic, Milos Prvulovic |
MICRO | 3 |
| 2016 | Statistical Modeling and Simulation of Short-Range Device-to-Device Communication Channels at Sub-THz FrequenciesabstractA 2-D geometrical propagation model for short-range device-to-device desktop communication channels at sub-terahertz (sub-THz) frequencies is proposed. Based on the geometrical model, a parametric reference model for short-range sub-THz multipath fading channels is developed. From the reference model, the corresponding frequency correlation function and the power delay profile (PDP) are derived and compared with the measured data. The results show good agreement between the measured and theoretical PDPs. Finally, a new sum-of-sinusoids-based simulation model for wideband sub-THz channels is proposed. The statistics of the reference model are verified by simulation. The results show that the simulation model is a good approximation of the reference model. Alenka G. Zajic |
IEEE Trans. Wirel. Commun. | 2 |
| 2015 | FASE: finding amplitude-modulated side-channel emanationsabstractWhile all computation generates electromagnetic (EM) side-channel signals, some of the strongest and farthest-propagating signals are created when an existing strong periodic signal (e.g. a clock signal) becomes stronger or weaker (amplitude-modulated) depending on processor or memory activity. However, modern systems create emanations at thousands of different frequencies, so it is a difficult, error-prone, and time-consuming task to find those few emanations that are AM-modulated by processor/memory activity. Robert Locke Callan, Alenka G. Zajic, Milos Prvulovic |
ISCA | 2 |
| 2014 | A Practical Methodology for Measuring the Side-Channel Signal Available to the Attacker for Instruction-Level EventsabstractThis paper presents a new metric, which we call Signal Available to Attacker (SAVAT), that measures the side channel signal created by a specific single-instruction difference in program execution, i.e. The amount of signal made available to a potential attacker who wishes to decide whether the program has executed instruction/event A or instruction/event B. We also devise a practical methodology for measuring SAVAT in real systems using only user-level access permissions and common measurement equipment. Finally, we perform a case study where we measure electromagnetic (EM) emanations SAVAT among 11 different instructions for three different laptop systems. Our findings from these experiments confirm key intuitive expectations, e.g. That SAVAT between on-chip instructions and off-chip memory accesses tends to be higher than between two on-chip instructions. However, we find that particular instructions, such as integer divide, have much higher SAVAT than other instructions in the same general category (integer arithmetic), and that last-level-cache hits and misses have similar (high) SAVAT. Overall, we confirm that our new metric and methodology can help discover the most vulnerable aspects of a processor architecture or a program, and thus inform decision-making about how to best manage the overall side channel vulnerability of a processor, a program, or a system. Robert Locke Callan, Alenka G. Zajic, Milos Prvulovic |
MICRO | 2 |
| 2014 | Experimental Verification of the Non-Stationary Statistical Model for V2V Scatter ChannelsabstractThis paper compares our non-stationary geometric- stochastic channel model for vehicle-to-vehicle scatter channels with measurement data collected in a vehicle-to-vehicle measurement campaign. The measurements were conducted on a forest road near Munich at 5.2 GHz using a car mounted transmitter and receiver platform. The data is evaluated in terms of delay and Doppler frequency and then compared to a scaled version of the joint delay Doppler probability density function. The close agreement between the analytical and empirical data confirms the utility of our non-stationary geometric stochastic model. Michael Walter 0002, Uwe-Carsten Fiebig, Alenka G. Zajic |
VTC Fall | 3 |
| 2013 | Traffic steering between a low-latency unswitched TL ring and a high-throughput switched on-chip interconnectabstractGrowth in core count creates an increasing demand for interconnect bandwidth, driving a change from shared buses to packet-switched on-chip interconnects. However, this increases the latency between cores separated by many links and switches. In this paper, we show that a low-latency unswitched interconnect built with transmission lines can be synergistically used with a high-throughput switched interconnect. First, we design a broadcast ring as a chain of unidirectional transmission line structures with very low latency but limited throughput. Then, we create a new adaptive packet steering policy that judiciously uses the limited throughput of this ring by balancing expected latency benefit and ring utilization. Although the ring uses 1.3% of the on-chip metal area, our experimental results show that, in combination with our steering, it provides an execution time reduction of 12.4% over a mesh-only baseline. Jungju Oh, Alenka G. Zajic, Milos Prvulovic |
PACT | 2 |
| 2013 | Envelope level crossing rate in mobile-to-mobile underwater fading channelsabstractAn analytical model for mobile-to-mobile underwater communications is presented. From the analytical model, the envelope level crossing rate is derived for a non-isotropic scattering environment. The obtained analytical results are compared with measured data. The close agreement between the analytical and empirical curves confirms the utility of the proposed model. Bryan Blankenagel, Alenka G. Zajic |
ICC | 2 |
| 2013 | Simulation Model for Wideband Mobile-to-Mobile Underwater Fading ChannelsabstractThis paper presents a two-dimensional (2-D) reference model for wideband mobile-to-mobile (M-to-M) underwater fading channels. From the reference model, the timefrequency correlation function for a 2-D non-isotropic scattering environment is derived. Finally, the sum-of-sinusoids simulator is presented and shown to closely match the statistical properties of the reference model. Bryan Blankenagel, Alenka G. Zajic |
VTC Spring | 2 |
| 2011 | TLSync: support for multiple fast barriers using on-chip transmission linesabstractAs the number of cores on a single-chip grows, scalable barrier synchronization becomes increasingly difficult to implement. In software implementations, such as the tournament barrier, a larger number of cores results in a longer latency for each round and a larger number of rounds. Hardware barrier implementations require significant dedicated wiring, e.g., using a reduction (arrival) tree and a notification (release) tree, and multiple instances of this wiring are needed to support multiple barriers (e.g., when concurrently executing multiple parallel applications). Jungju Oh, Milos Prvulovic, Alenka G. Zajic |
ISCA | 3 |
| 2011 | Estimation of Velocities in Mobile-to-Mobile Wireless Fading ChannelsabstractThis paper proposes a new crossing-rate-based estimator that jointly estimates velocities of both the transmitter and receiver in mobile-to-mobile communications (M-to-M). The proposed estimator is designed for narrow-band wireless M-to-M communications over noise-free isotropic fading channels. The proposed estimator is evaluated through extensive computer simulations and the results show that the proposed algorithm provides very good estimation accuracy. Furthermore, the proposed estimator is tested in the presence of a non-isotropic scattering, line-of-sight propagation, and Gaussian noise and the results show that the good estimation accuracy is preserved. Alenka G. Zajic |
VTC Fall | 1 |
| 2010 | Statistical Modeling of Underwater Wireless ChannelsabstractThis paper proposes a geometry-based statistical model for multiple-input multiple-output shallow water wireless channels. From the reference model, the corresponding space-time-frequency correlation function and space-Doppler power spectral density are derived. To verify our results, the derived statistics are compared with the experimentally obtained channel statistics and close agreement is observed. Alenka G. Zajic |
GLOBECOM | 1 |
| 2009 | Impact of Mutual Coupling on MIMO Vehicle-to-Vehicle SystemsabstractThis paper proposes a three-dimensional (3-D) model for wideband multiple-input multiple-output (MIMO) vehicle-to-vehicle (V-to-V) multipath fading channels that accounts for mutual coupling among both, transmit and receive antenna elements. From the 3-D model, the spatial correlation is derived for a 3-D non-isotropic scattering environment. Finally, this model is used to evaluate the effect of mutual coupling on the antenna element patterns, spatial correlation, and received power of MIMO V-to-V systems in urban environments. Alenka G. Zajic |
GLOBECOM | 1 |
| 2009 | A space-time code design for CPM: diversity order and coding gainabstractSufficient conditions are derived under which$M$-ary partial- and full-response continuous phase modulation (CPM) space–time (ST) codes will attain both full spatial diversity and optimal coding gain. General code construction rules are desirable due to the nonlinearity and inherent memory of the CPM signals which makes manual design or computer search difficult. Using a linear decomposition of CPM signals with tilted phase, we identify a rank criterion for$M$-ary partial- and full-response CPM that specifies the set of allowable modulation indices. We also propose a coding gain design criterion. Optimization of the coding gain for CPM ST codes is shown to depend on the CPM frequency/phase shaping pulse, modulation index, and codewords. The modulation indices and phase shaping functions that improve the coding gain are specified. Finally, optimization of coding gain for ST-CPM and orthogonal ST-CPM codewords is discussed. Alenka G. Zajic, Gordon L. Stüber |
IEEE Trans. Inf. Theory | 1 |
| 2009 | Three-dimensional modeling and simulation of wideband MIMO mobile-to-mobile channelsabstractA three-dimensional (3-D) geometrical propagation model for wideband multiple-input multiple-output (MIMO) mobile-to-mobile (M-to-M) communications is proposed. Based on the geometrical model, a 3-D parametric reference model for wideband MIMO M-to-M multipath fading channels is developed. From the reference model, the corresponding space-time-frequency correlation function is derived for a 3-D non-isotropic scattering environment. It is shown that the time and frequency dispersion of a wide sense stationary uncorrelated scattering channel cannot be treated independently, contrary to common practice. From the space-time-frequency correlation function, the space-Doppler power spectral density and the power space-delay spectrum are derived and compared with measured data. Finally, a new sum-of-sinusoids based simulation model for wideband MIMO M-to-M Ricean fading channels is proposed. The statistics of the simulation model are verified by simulation. The results show that the simulation model is a good approximation of the reference model. Alenka G. Zajic, Gordon L. Stüber |
IEEE Trans. Wirel. Commun. | 1 |
| 2008 | Maximum Likelihood Method for MIMO Mobile-to-Mobile Channel Parameter EstimationabstractA three-dimensional reference model for wideband multiple-input multiple-output mobile-to-mobile channels is reviewed. To allow comparison between the proposed model and measured data, a new maximum likelihood based stochastic estimator is derived. The proposed estimator extracts the relevant model parameters from the measured data. The performance of the new estimator is evaluated by deriving the Cramer-Rao lower bound (CRLB) and by comparing the mean square error of the parameter estimates to the CRLB. Simulation results show that the proposed estimator has an asymptotically optimal performance, since it reaches the CRLB for a small number of samples. Alenka G. Zajic, Gordon L. Stüber |
GLOBECOM | 1 |
| 2008 | Envelope Level Crossing Rate and Average Fade Duration in Mobile-To-Mobile Fading ChannelsabstractA three-dimensional (3-D) analytical model for mobile-to-mobile communications is presented. From the analytical model, the envelope level crossing rate and average fade duration are derived for a 3-D non-isotropic scattering environment. The obtained analytical results are compared with measured data. The close agreement between the analytical and empirical curves confirms the utility of the proposed model. Alenka G. Zajic, Gordon L. Stüber, Thomas G. Pratt |
ICC | 1 |
| 2008 | Statistical modeling and experimental verification of wideband MIMO mobile-to-mobile channels in highway environmentsabstractA three-dimensional reference model for wideband multiple-input multiple-output (MIMO) mobile-to-mobile (M-to-M) channels is reviewed. To validate the reference model, an experimental MIMO M-to-M channel-sounding campaign was conducted for M-to-M vehicular communication with vehicles travelling along expressways in a metropolitan area. The measured data is processed and the channel statistics obtained from the reference model and from the empirical measurements are compared. The close agreement between the analytically and empirically obtained channel statistics confirms the utility of the proposed reference model. Alenka G. Zajic, Gordon L. Stüber, Thomas G. Pratt |
PIMRC | 1 |
| 2008 | Performance Analysis of a System using Coordinate Interleaving and Constellation Rotation in Rayleigh Fading ChannelsabstractDiversity can play an important role in the performance improvement of a communication system in fading channels. The achievable performance with signal space diversity (SSD) is analyzed and a closed form expression for the upper bound of average probability of bit error (Pb) for M-ary phase shift keying (MPSK) in Rayleigh fading channel is presented. The problem of calculating Pbof coherent MPSK over a Rayleigh fading channel has been studied previously in the literature. A solution based on the nearest neighbors was given. In this paper we show that the results with the nearest neighbor approximation represent an expurgated bound and are only valid for a small range of rotational angles. Exact pair-wise error probability (PEP) is derived for Rayleigh fading channels. It is shown that Gray signal constellation mapping is not necessarily the best option for a system employing coordinate interleaving and constellation rotation. Rotation angles are optimized by finding the minimum of the upper bound of Pb. It is shown that the new derived bound is tight for the entire range of rotational angles at high signal-to-noise ratio. Furthermore, the performance of the system in case of phase estimation error is also investigated by simulations. Nauman F. Kiyani, Jos H. Weber, Alenka G. Zajic, Gordon L. Stüber |
VTC Fall | 3 |
| 2008 | Statistical Properties of Wideband MIMO Mobile-to-Mobile Channels (Special Paper)abstractA three-dimensional (3-D) theoretical model for wideband multiple-input multiple-output (MIMO) mobile-to- mobile (M-to-M) channels is presented. Based on this model, the statistical properties of wideband MIMO M-to-M channels are derived. In particular, the space-time-frequency correlation function, the power space-delay spectral density, and the envelope level crossing rate are derived for a 3-D non-isotropic scattering environment. Finally, to validate the theoretical derivations, some simulation results are presented and compared with measured data. Alenka G. Zajic, Gordon L. Stüber |
WCNC | 1 |
| 2007 | A Three Dimensional Parametric Model for Wideband MIMO Mobile-to-Mobile ChannelsabstractA three-dimensional (3-D) geometrical propagation model for wideband multiple-input multiple-output (MIMO) mobile-to-mobile (M-to-M) communications is proposed. Based on the geometrical model, a 3-D parametric reference model for wideband MIMO M-to-M multipath fading channels is developed. From the reference model, the space-time-frequency correlation function and the space-Doppler power spectral density are derived for a 3-D non-isotropic scattering environment. Finally, some simulation results are presented and compared with measured data. The close agreement between the theoretical and empirical curves confirms the utility of the proposed wideband model. Alenka G. Zajic, Gordon L. Stüber |
GLOBECOM | 1 |
| 2007 | A Space-Time Code Design for Partial-Response CPM: Diversity Order and Coding GainabstractUsing a linear decomposition of continuous phase modulated (CPM) signals with tilted-phase, sufficient conditions are derived under whichM-ary partial-response CPM space-time codes will attain both full spatial diversity and optimal coding gain. A rank criterion forM-ary partial-response CPM that specifies the set of allowable modulation indices is identified. Furthermore, optimization of the coding gain for CPM space-time codes is shown to depend on the CPM frequency/phase shaping pulse, modulation index, and codewords. The modulation indices and phase shaping functions that optimize the coding gain are specified. Finally, optimization of CPM space-time codewords is discussed. Alenka G. Zajic, Gordon L. Stüber |
ICC | 1 |
| 2007 | Influence of 3-D Spatial Correlation on the Capacity of MIMO Mobile-to-Mobile ChannelsabstractA three-dimensional (3-D) theoretical model for MIMO mobile-to-mobile (M-to-M) multipath fading channels is proposed and its spatial correlation function is derived. This correlation function is used to evaluate the effect of spatial correlation on the capacity of uniform linear antenna arrays. The effects of antenna spacing and antenna orientations on capacity are studied. Alenka G. Zajic, Gordon L. Stüber |
VTC Spring | 1 |
| 2007 | A Three-Dimensional MIMO Mobile-to-Mobile Channel ModelabstractA three-dimensional (3-D) geometrical propagation model for multi-input-multi-output (MIMO) mobile-to-mobile (M-to-M) communications is proposed. Based on the geometrical model, a 3-D reference model for MIMO M-to-M multipath fading channels is proposed. From the reference model, a closed-form joint space-time correlation function is derived for a 3-D non-isotropic scattering environment and it is show that many existing correlation functions are special cases of the derived space-time correlation function. Alenka G. Zajic, Gordon L. Stüber |
WCNC | 1 |
| 2006 | Optimization of Coding Gain for Full-Response CPM Space-Time CodesabstractConditions are derived under which M-ary full-response CPM space-time codes will attain full spatial diversity and optimal coding gain. General code construction rules are desirable due to the nonlinearity and inherent memory of CPM signals which make manual design or computer search difficult. Optimization of the coding gain for CPM space-time codes is shown to depend on the CPM frequency/phase shaping pulse, modulation index, and codewords. The modulation indices and phase shaping functions that optimize the coding gain are specified. Finally, optimization of ST-CPM codewords is discussed. Alenka G. Zajic, Gordon L. Stüber |
GLOBECOM | 1 |
| 2006 | Space-Time Correlated MIMO Mobile-To-Mobile ChannelsabstractA theoretical model is proposed for multi-input-multi-output (MIMO) mobile-to-mobile (M-to-M) Rayleigh fading channels, such that the complex faded envelope does not depend on the distance between scatterers and antenna elements. From this model, a closed-form joint space-time correlation function is derived for 2-D non-isotropic scattering environment. Also, a space-frequency power density spectrum of the complex faded envelope is derived, assuming 2-D isotropic scattering environment. Finally, a statistical simulation model for MIMO M-to-M Rayleigh fading channels is proposed. The space-time correlation function of the simulation model is derived and verified by simulation, and an adaptive method for choosing the number of scatterers in simulations is proposed. The results show that the statistical simulation model is a good approximation of the theoretical model Alenka G. Zajic, Gordon L. Stüber |
PIMRC | 1 |
| 2006 | A new simulation model for mobile-to-mobile Rayleigh fading channelsabstractA new statistical sum-of-sinusoids simulation model is proposed for mobile-to-mobile Rayleigh fading channels and compared with existing simulation models. The new proposed model has a lower variance of the auto-correlation functions, i.e., it converges faster and has a lower correlation between the in-phase and quadrature components of the complex faded envelope than existing simulation models. This model yields adequate statistics with only 30 simulation runs Alenka G. Zajic, Gordon L. Stüber |
WCNC | 1 |
| 2006 | Efficient simulation of rayleigh fading with enhanced de-correlation propertiesabstractNew sum-of-sinusoids simulation models are proposed for Rayleigh fading channels and compared with existing simulation models. First, an ergodic statistical ("deterministic") model is proposed that, compared to existing models, yields a significantly lower cross-correlation between different complex envelopes and between the quadrature components of each complex envelope. However, the auto-correlation functions of the quadrature components still do not match the theoretical functions. To overcome this disadvantage, we also propose a new statistical simulator that converges faster than existing statistical models, and has lower cross-correlations between different complex envelopes and between the quadrature components of each complex envelope. This new statistical model yields adequate statistics with only 30 simulation runs Alenka G. Zajic, Gordon L. Stüber |
IEEE Trans. Wirel. Commun. | 1 |