EdX

Between Physical and Sofware: Fault Attacks, Side Channels, and Mitigations (edX)

Between Physical and Sofware: Fault Attacks, Side Channels, and Mitigations (edX)

Fault attacks (sometimes also called active side-channel attacks ) are a very powerful means that goes beyond just leaking secrets from an application or device, to actively manipulating it. We will look at fault attacks that can be triggered from software, namely Rowhammer and Plundervolt. We will also learn that some transient-execution attacks have some similarities to fault attacks. You will implement some of these attacks yourself and learn how they are mitigated.

Class Deals by MOOC List - Click here and see EdX's Active Discounts, Deals, and Promo Codes.

In this course, we build upon the knowledge we built up on cache side-channel attacks and transient-execution attacks, as well as the side-channel and security mindset. We again go beyond software-based side-channel attacks and now study software-based fault attacks. Fault attacks (sometimes also called active side-channel attacks ) are an incredibly powerful means to attack a system. Instead of just leaking secrets from an application or device, fault attacks actively manipulate the application or device to induce incorrect behavior which lets the attacker again leak secrets or fully take over control and subvert the application or device. We will look at fault attacks that can be triggered from software, namely Rowhammer and Plundervolt. We will then draw the connection between these attacks and transient-execution attacks that share some similarities. You will implement some of these attacks yourself and learn how they are mitigated.
This course is part of the Side Channel Security – Transient Execution and Fault Attacks Professional Certificate.

Prerequisites:
Knowledge and skills from the prerequisite courses Side Channel Security S3: Cache Side-Channel Attacks and Mitigations , Side Channel Security S4: Physical and Advanced Side-Channel Attacks , and Side Channel Security S5: Transient-Execution Attacks are strongly recommended.
We expect C and C++ programming skills on a similar level as in the prerequisite course. You may have obtained these as part of a university program such as computer science or a high school degree with a focus on computer science.

What you'll learn

  • Understand different methods to induce hardware faults from software on modern computers
  • Understand how these faulting mechanisms can undermine a system's security
  • Understand the security risks posed and how fault attacks can be mitigated

Syllabus

  • Episode 1: Sledge Hammer!

Attackers can fault hardware from software using Rowhammer.

  • Episode 2: Under Voltage

Plundervolt similarly can induce faults.

  • Episode 3: Load Value Inception

Injecting false values also works in the transient domain and without any physical fault.

  • Episode 4: Power Leakers

Software exposes power consumption interfaces, enabling leakage.

  • Episode 5: Hardware Leaks and Software Leaks

The page cache can be used for attacks similar to hardware caches.

Go to Class
MOOC List is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Related Courses

Finding your Cybersecurity Career Path (edX) EdX
University of Washington,UWashingtonX

Finding your Cybersecurity Career Path (edX)

Learn about different career pathways in cybersecurity and complete a self-assessment project to better understand the right path for you. In this course, you will focus on the pathways to cybersecurity career success. You will determine your own incoming skills, talent, and deep interests to apply toward a meaningful and informed exploration of 32 Digital Pathways of Cybersecurity.

Self Paced
Self-Paced
Beginners Guide to Cybersecurity (edX) EdX
IBM

Beginners Guide to Cybersecurity (edX)

This course is designed for beginners to build critical skills to address common security threats, and adopt best practices for reducing risks. A tech talent shortage continues as organizations adopt higher security standards to address the ongoing risk of threats and breaches. This course builds key skills to address common security threats and risks and provides best practices to guard against them.

Self Paced
Self-Paced
Ciberseguridad. Bases y estructuras para la protección de la información (edX) EdX
Universidad Anáhuac,AnahuacX

Ciberseguridad. Bases y estructuras para la protección de la información (edX)

Sé capaz de blindar tu información y la de tu empresa contra las amenazas informáticas y conoce los fundamentos del fascinante mundo de la ciberseguridad. En la actualidad el acceso a las bases de datos, a las redes de computadoras y la información en la nube es esencial para desempeñar gran parte de nuestras actividades cotidianas.

Self Paced
Self-Paced
Side-Channel Security: Developing a Side-Channel Mindset (edX) EdX
Graz University of Technology,TUGrazX

Side-Channel Security: Developing a Side-Channel Mindset (edX)

Side channels are everywhere. They are incredibly powerful and have disrupted the world in the last years, especially with attacks like Meltdown and Spectre that impacted most computers on the planet. You also have seen side channels and used them already yourself. In this course, you will learn and practice the side-channel mindset and how to spot side channels in the real-world and how to use them in non-technical and semi-technical settings.

Self Paced
Self-Paced
E-Payment (edX) EdX
University of Hong Kong,HKUx

E-Payment (edX)

Master the technologies behind e-payment systems and learn about their security mechanisms. Electronic payments have become an integral part of our daily lives. This in-depth course is designed to give students a thorough grasp of various e-payment systems, their underlying technology, and the security measures and regulations that ensure their safe and efficient use.

Self Paced
Self-Paced
Arctic Security Fundamentals (edX) EdX
University of Alaska Fairbanks,AlaskaX

Arctic Security Fundamentals (edX)

This course explores the present-day security situation of the Arctic through a focus on the key stakeholders responsible for diplomacy and defense. The Arctic: a region of frigid waters, tundra, and prolonged periods of light and darkness. While it may seem desolate, the Circumpolar North holds a wealth of resources and opportunities for nations and the Indigenous peoples who live there.

Self Paced
Self-Paced
Quantum Cryptography (edX) EdX
Caltech,Delft University of Technology

Quantum Cryptography (edX)

Learn how quantum communication provides security that is guaranteed by the laws of nature. How can you tell a secret when everyone is able to listen in? In this course, you will learn how to use quantum effects, such as quantum entanglement and uncertainty, to implement cryptographic tasks with levels of security that are impossible to achieve classically.

No sessions available
5-12 Weeks
Cybersecurity Capstone and Case Studies (edX) EdX
IBM

Cybersecurity Capstone and Case Studies (edX)

Research real-world data breaches and explore different incident response methodologies and security models. This course is part of the IBM Cybersecurity Analyst Professional Certificate! Throughout this course, you will delve into incident response methodologies and security models through case studies, equipping yourself with effective strategies for handling security incidents. You will also learn to identify and categorize various types of vulnerabilities and associated attacks commonly faced by modern organizations.

Self Paced
Self-Paced