Outils pour l'analyse de code et de contre-mesures pour l'injection de fautes multiples

Etienne Boespflug · HAL (Le Centre pour la Communication Scientifique Directe) · 2023

Active attackers are able to modify the behavior of the program during its execution. In particular, fault injection attacks, which originally emerged as a method of testing against accidental hardware faults, are a powerful attack vector in which the attacker can inject faults during execution using physical techniques such as laser beams, or voltage or frequency glitches. More recently, software fault injection methods have been proposed.This thesis focuses on analyzing programs in the context of fault injection attacks, and more particularly multiple faults, which implies that the attacker is able to combine several faults to complete an attack.Combined attacks make more difficult the evaluation of the robustness of programs by tools because of the combinatorial explosion of the execution paths due to faults.This manuscript presents the different contributions of this thesis.First, the robustness analysis tool Lazart has been developed during this thesis, aiming at helping thesearch of attacks on software in a multi-fault context.The evaluation of protections against this type of attacks has also been an important topic of this thesis and contribution are presented to assist the placement of software countermeasures.Finally, the placement tools used in the literature are often based on a trial-and-error approach that is not adapted to multiple fault contexts, and they rarely address the verification that these protections are effectively useful in the program. A methodology to optimize the placement of countermeasures has been developed, able to determine which portions of the protections in a program can be removed, while maintaining the same level of security.

Read the paper · More papers on PaperTik