Raccoon: closing digital side-channels through obfuscated execution
Ashay Rane, Calvin Lin, Mohit Tiwari · 2015
Side-channel attacks monitor some aspect of a com-puter system’s behavior to infer the values of secret data. Numerous side-channels have been exploited, including those that monitor caches, the branch predictor, and the memory address bus. This paper presents a method of defending against a broad class of side-channel attacks, which we refer to as digital side-channel attacks. The key idea is to obfuscate the program at the source code level to provide the illusion that many extraneous pro-gram paths are executed. This paper describes the techni-cal issues involved in using this idea to provide confiden-tiality while minimizing execution overhead. We argue about the correctness and security of our compiler trans-formations and demonstrate that our transformations are safe in the context of a modern processor. Our empiri-cal evaluation shows that our solution is 8.9 × faster than prior work (GhostRider [20]) that specifically defends against memory trace-based side-channel attacks. 1