A Side Channel Attack Detection System Using Processor Core Events and a Support Vector Machine

A method for the detection and suppression of side band channel attacks has been proposed and evaluated using machine learning and processor core events. A supervised learning model is used in the implementation of a system based on hardware event counters to detect malicious exploits such as SPECTRE variants running in a process on a Linux based system operating as an Edge computing device. The approach uses existing on-chip hardware to detect variants of malicious exploitation in the midst of other application processes and suspend the offending process. In this work we analyze multiple variants of side channel attack and demonstrate how our detection system can be trained to detect and react to multiple attacks simultaneously. We demonstrate this prototype on variants of the classic SPECTRE attack such as the micro-ops cache attack based on x86 based machines. We use dimensionality reduction techniques and feature selection techniques from a large set of counter data to improve performance results. The detection system has successfully performed on multiple instruction set architectures including x86 as well as Cortex-A class ARM architectures.

Paper

Full text

PDF

A Side Channel Attack Detection System Using Processor Core Events and a Support Vector Machine

Semantic Scholar · Computer Science · 2022

Abstract

A method for the detection and suppression of side band channel attacks has been proposed and evaluated using machine learning and processor core events. A supervised learning model is used in the implementation of a system based on hardware event counters to detect malicious exploits such as SPECTRE variants running in a process on a Linux based system operating as an Edge computing device. The approach uses existing on-chip hardware to detect variants of malicious exploitation in the midst of other application processes and suspend the offending process. In this work we analyze multiple variants of side channel attack and demonstrate how our detection system can be trained to detect and react to multiple attacks simultaneously. We demonstrate this prototype on variants of the classic SPECTRE attack such as the micro-ops cache attack based on x86 based machines. We use dimensionality reduction techniques and feature selection techniques from a large set of counter data to improve performance results. The detection system has successfully performed on multiple instruction set architectures including x86 as well as Cortex-A class ARM architectures.

Similar papers

© 2026 NYSGPT2525 LLC