You are here : Home > SL-DRT-24-0541

Theses

SL-DRT-24-0541

Published on 7 December 2023
SL-DRT-24-0541
Research fieldCyber security : hardware and sofware

Domaine-SComputer science and software

ThemeTechnological challenges

Theme-SEngineering sciences

Field
Cyber security : hardware and sofware Technological challenges Computer science and software Engineering sciences DRT DSYS SSSEC LTSO Grenoble http://thomashk0.github.io/pages/about.html http://www.leti-cea.com/cea-tech/leti/english/Pages/Applied-Research/Facilities/cyber-security-platform.aspx
Title
Design and Analysis of Side-Channel Feedback for Vulnerability Discovery
Abstract
Fuzzing is a dynamic testing technique that enables vulnerabilities to be discovered very efficiently. Hundreds or even thousands of vulnerabilities are detected (and repaired) every year in the software we use. When we try to transpose the fuzzing approach to embedded systems, we are faced with a number of problems: the source code is not always available, very little information is available about the behaviour of the system at runtime and, finally, it is difficult to detect whether a bug has appeared. For several years now, the LTSO laboratory has been developing state-of-the-art techniques for analysing auxiliary channels, in particular the electromagnetic radiation produced by systems during operation. These measurements make it possible to infer information (data, executed code) about the behaviour of the system in a non-intrusive way. The aim of this thesis is therefore to determine whether these side-channel measurements can be used to improve the fuzzing process on embedded systems. The use of this new source of information also opens the door to the discovery of new classes of vulnerabilities, such as micro-architectural vulnerabilities. The PhD will take place at CEA Grenoble, within the LETI institute, in a research team dedicated to the study and development of solutions for the security of present and future electronic systems (http://www.leti-cea.com/cea-tech/leti/english/Pages/Applied-Research/Facilities/cyber-security-platform.aspx). Translated with www.DeepL.com/Translator (free version)
Formation
Master 2 Technological Research
Contact person
HISCOCK Thomas CEA DRT/DSYS/SSSEC/LSOSP 17 Avenue des Martyrs, 38000 Grenoble 04.38.78.94.02 thomas.hiscock@cea.fr
University/ graduate school
Université Grenoble Alpes Electronique, Electrotechnique, Automatique, Traitement du Signal (EEATS)
Thesis supervisor
INPG-ESISAR/LCIS
Location
Département Systèmes (LETI) Service Sécurité des Systèmes Electroniques et des Composants Laboratoire de Tests de Sécurité & leurs Outils
Start1/2/2024

Go back to list