Introduction to the FIRST Special Issue
Andrew Nicholas Cormack, Jeroen van der Ham · Digital Threats Research and Practice · 2020
The Forum of Incident Response and Security Teams (FIRST) has held annual conferences around the world since 1989.They have always been fruitful places to exchange ideas: many developments in security and incident response can be traced back to discussions at FIRST conferences.For the first time, the 2019 conference in Edinburgh specifically targeted academic researchers, hoping to broaden these discussions further.We wanted to enable incident response practitioners to learn from the latest research and researchers to test their ideas against the practical experience of more than 1,000 conference delegates.Presenters were invited to submit journal papers describing their work for this special issue of ACM Digital Threats: Research and Practice.The range of topics-from hardware exploits to process improvements-gives some impression of the breadth of the conference.We are particularly pleased that the authors include both academics and practitioners: a sign, perhaps, that our goal of enabling cross-fertilisation was successful.Papers describing attacks on cryptographic systems can sometimes appear rather theoretical.In "SCA-Pittaya: A Practical and Affordable Side-Channel Attack Setup for Power Leakage-Based Evaluations", François and Marc Durvaux describe a very practical experiment to recover cryptographic keys from two common Internet of Things (IoT) devices.They first monitor the power consumption of the 8-bit and 32-bit Arduino boards, recording the electromagnetic radiation emitted as they perform a small number of cryptographic operations using the 256-bit Advanced Encryption Standard algorithm.The resulting signal traces are then subject to statistical analysis to recover the secret keys.Even using the simplest correlation power analysis technique, the key can be recovered with high probability from just 350 traces: with preprocessing, this can be reduced to approximately 50, corresponding to less than a minute of recording.Perhaps the most striking achievement is that this does CCS Concepts: • Security and privacy → Cryptanalysis and other attacks; Embedded systems security; Malware and its mitigation; Intrusion detection systems; Usability in security and privacy; • Social and professional topics → System management;