Hot-n-Cold: Mapping the Syscall Attack Surface Using Thermal Side Channels

Teodora Vasilas, Thomas Jakobsche, Florina M. Ciorba · 2023

As we increasingly rely on digital technologies, cyber security is of paramount importance. While computing systems offer numerous advantages, they also introduce unwanted security risks. In High Performance Computing, security risks have largely been ignored in the name of high performance [1]. Nevertheless, ensuring security and privacy of computations and data is essential [2]. Linux operating systems, running on all Top500 HPC systems, use kernel and user modes to implement security, which prevents unauthorized access to critical kernel functions. System calls connect the two modes. Therefore, they were frequently attacked, as reported in over 100 Common Vulnerabilities and Exposures (CVEs) in the last 7 years [3]. Combining static and dynamic syscalls analysis [4] [5] has recently been shown to be imperative for creating a syscalls whitelist, to minimize the potential attack surface they introduce. This work introduces a novel dynamic analysis technique, Hot-n-Cold, to detect anomalies in the Linux commands’ behavior by monitoring the CPU temperature. We use Hot-n-Cold to map the syscall attack surface on a local HPC system. Hot-n-Cold can be extended and applied to detect, in real-time, an anomaly that may facilitate creation of an attack. The results on two Linux frequently used commands (ls & chmod) show a positive correlation of up to 80% between the original Linux command and a version augmented with syscalls from CVEs. This work shows the importance of security in HPC, and motivates further research into studying and designing security mechanisms that preserve high performance.

Read the paper · More papers on PaperTik