Towards a Black-Box Security Evaluation Framework - Equipe Secure and Safe Hardware Accéder directement au contenu
Chapitre D'ouvrage Année : 2021

Towards a Black-Box Security Evaluation Framework

Mosabbah Mushir Ahmed
  • Fonction : Auteur
Youssef Souissi
  • Fonction : Auteur
  • PersonId : 971834
Oualid Trabelsi
  • Fonction : Auteur
Sylvain Guilley
Antoine Bouvet
  • Fonction : Auteur
Sofiane Takarabt
  • Fonction : Auteur
  • PersonId : 1198346

Résumé

Injection of faults has been studied in various research works since last decades. Several hardware targets have been studied with respect to the efficiency of fault injections. In this paper we address the security evaluation of embedded systems in constrained environments called black-box analyses. This is not considered by standards of evaluation as they require conducting the analysis in the most relaxed conditions, often called white-box analysis which focuses on specific security modules provided that the finer details are available. However, black-box analysis has a much larger view by focusing on all the system as potential target. It is closer to a real world attacker. This allows measuring the impact of real attack scenarios, and therefore thinking and building the most adequate protections. We put forward a six steps evaluation methodology along with a practical use-case on a real end-user device. This shall give a better understanding and also an evaluation framework of black-box analysis.
Fichier principal
Vignette du fichier
submission_v.2.0__ICSP.pdf (6.4 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03788731 , version 1 (27-09-2022)

Identifiants

Citer

Mosabbah Mushir Ahmed, Youssef Souissi, Oualid Trabelsi, Sylvain Guilley, Antoine Bouvet, et al.. Towards a Black-Box Security Evaluation Framework. Security and Privacy Second International Conference, ICSP 2021, Jamshedpur, India, November 16–17, 2021, Proceedings, 1497, Springer International Publishing, pp.79-92, 2021, Communications in Computer and Information Science, ⟨10.1007/978-3-030-90553-8_6⟩. ⟨hal-03788731⟩
31 Consultations
64 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More