SILENT: A New Lens on Statistics in Software Timing Side Channels

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Dunsche, Martin, Bastian, Patrick, Maehren, Marcel, Erinola, Nurullah, Merget, Robert, Bissantz, Nicolai, Dette, Holger, Schwenk, Jörg
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909595950120960
author Dunsche, Martin
Bastian, Patrick
Maehren, Marcel
Erinola, Nurullah
Merget, Robert
Bissantz, Nicolai
Dette, Holger
Schwenk, Jörg
author_facet Dunsche, Martin
Bastian, Patrick
Maehren, Marcel
Erinola, Nurullah
Merget, Robert
Bissantz, Nicolai
Dette, Holger
Schwenk, Jörg
contents Cryptographic research takes software timing side channels seriously. Approaches to mitigate them include constant-time coding and techniques to enforce such practices. However, recent attacks like Meltdown [42], Spectre [37], and Hertzbleed [70] have challenged our understanding of what it means for code to execute in constant time on modern CPUs. To ensure that assumptions on the underlying hardware are correct and to create a complete feedback loop, developers should also perform \emph{timing measurements} as a final validation step to ensure the absence of exploitable side channels. Unfortunately, as highlighted by a recent study by Jancar et al. [30], developers often avoid measurements due to the perceived unreliability of the statistical analysis and its guarantees. In this work, we combat the view that statistical techniques only provide weak guarantees by introducing a new algorithm for the analysis of timing measurements with strong, formal statistical guarantees, giving developers a reliable analysis tool. Specifically, our algorithm (1) is non-parametric, making minimal assumptions about the underlying distribution and thus overcoming limitations of classical tests like the t-test, (2) handles unknown data dependencies in measurements, (3) can estimate in advance how many samples are needed to detect a leak of a given size, and (4) allows the definition of a negligible leak threshold $Δ$, ensuring that acceptable non-exploitable leaks do not trigger false positives, without compromising statistical soundness. We demonstrate the necessity, effectiveness, and benefits of our approach on both synthetic benchmarks and real-world applications.
format Preprint
id arxiv_https___arxiv_org_abs_2504_19821
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle SILENT: A New Lens on Statistics in Software Timing Side Channels
Dunsche, Martin
Bastian, Patrick
Maehren, Marcel
Erinola, Nurullah
Merget, Robert
Bissantz, Nicolai
Dette, Holger
Schwenk, Jörg
Cryptography and Security
Applications
Methodology
Cryptographic research takes software timing side channels seriously. Approaches to mitigate them include constant-time coding and techniques to enforce such practices. However, recent attacks like Meltdown [42], Spectre [37], and Hertzbleed [70] have challenged our understanding of what it means for code to execute in constant time on modern CPUs. To ensure that assumptions on the underlying hardware are correct and to create a complete feedback loop, developers should also perform \emph{timing measurements} as a final validation step to ensure the absence of exploitable side channels. Unfortunately, as highlighted by a recent study by Jancar et al. [30], developers often avoid measurements due to the perceived unreliability of the statistical analysis and its guarantees. In this work, we combat the view that statistical techniques only provide weak guarantees by introducing a new algorithm for the analysis of timing measurements with strong, formal statistical guarantees, giving developers a reliable analysis tool. Specifically, our algorithm (1) is non-parametric, making minimal assumptions about the underlying distribution and thus overcoming limitations of classical tests like the t-test, (2) handles unknown data dependencies in measurements, (3) can estimate in advance how many samples are needed to detect a leak of a given size, and (4) allows the definition of a negligible leak threshold $Δ$, ensuring that acceptable non-exploitable leaks do not trigger false positives, without compromising statistical soundness. We demonstrate the necessity, effectiveness, and benefits of our approach on both synthetic benchmarks and real-world applications.
title SILENT: A New Lens on Statistics in Software Timing Side Channels
topic Cryptography and Security
Applications
Methodology
url https://arxiv.org/abs/2504.19821