Combined software and hardware fault injection vulnerability detection

Given-Wilson, Thomas;Jafri, Nisrine;Legay, Axel
(2020) Innovations in Systems and Software Engineering — Vol. 16, n° 2, p. 101-120 (2020)

Files

main-journal.pdf
  • Open Access
  • Adobe PDF
  • 4.74 MB

Details

Authors
  • Given-Wilson, Thomasorcid-logoUCLouvain
    Author
  • Jafri, Nisrine
    Author
  • Legay, AxelUCLouvain
    Author
Abstract
Fault injection is a well known method to test the robustness and security vulnerabilities of software. Software-based and hardware-based approaches have been used to detect fault injection vulnerabilities. Software-based approaches typically rely upon simulations that can provide broad and rapid coverage, but may not correlate with genuine hardware vulnerabilities. Hardware-based experiments are indisputable in their results, but rely upon expensive expert knowledge and manual testing yielding ad-hoc and extremely limited results. Further, there is very limited connection between software-based simulation results and hardware-based experiments. This work bridges software-based and hardware-based fault injection vulnerability detection by contrasting results of both approaches. This demonstrates that: not all software-based vulnerabilities can be reproduced in hardware; prior conjectures on the fault model for Electro-Magnetic Pulse attacks may not be accurate; and that there is a co-relation between software-based and hardware-based approaches. Further, combining both approaches can yield a vastly more accurate and efficient approach to detecting genuine fault injection vulnerabilities.
Affiliations

Citations

Given-Wilson, T., Jafri, N., & Legay, A. (2020). Combined software and hardware fault injection vulnerability detection. Innovations in Systems and Software Engineering, 16(2), 101-120. https://doi.org/10.1007/s11334-020-00364-5 (Original work published 2020)