Side-channel attack
Computer security attack that exploits information leaked through observable side effects of the system's implementation
In computer security, a side-channel attack is a type of security exploit that uses information inadvertently leaked by a system—such as timing, power consumption, or electromagnetic or acoustic emissions—to gain unauthorized access to sensitive information. These attacks differ from those targeting flaws in the design of cryptographic protocols or algorithms (notwithstanding the fact that cryptanalysis may identify vulnerabilities relevant to both types of attacks).
Nº Q2267081 ★★
Uncommon · History
Side-channel attack
Computer security attack that exploits information leaked through observable side effects of the system's implementation
In computer security, a side-channel attack is a type of security exploit that uses information inadvertently leaked by a system—such as timing, power consumption, or electromagnetic or acoustic emissions—to gain unauthorized access to sensitive information. These attacks differ from those targeting flaws in the design of cryptographic protocols or algorithms (notwithstanding the fact that cryptanalysis may identify vulnerabilities relevant to both types of attacks).
Last price
—
Floor price
—
7-day median
—
30-day sales
0
30-day range
—
In circulation
0
Price history
median
low – high
sales
No sales in this period
Show table
| Date | median | Low | High | sales |
|---|
Sales history
- Last sale
- —
- 30-day average
- —
- 30-day low
- —
- 30-day high
- —
- Sales 7d
- 0
- Sales 30d
- 0
No sales yet.
Anonymous sales: no buyer or seller shown. Figures count player-to-player sales only.
From Wikipedia
In computer security, a side-channel attack is a type of security exploit that uses information inadvertently leaked by a system—such as timing, power consumption, or electromagnetic or acoustic emissions—to gain unauthorized access to sensitive information. These attacks differ from those targeting flaws in the design of cryptographic protocols or algorithms (notwithstanding the fact that cryptanalysis may identify vulnerabilities relevant to both types of attacks). Some side-channel attacks require technical knowledge of the internal operation of the system, others such as differential power analysis are effective as black-box attacks. The rise of Web 2.0 applications and software-as-a-service has also significantly raised the possibility of side-channel attacks on the web, even when transmissions between a web browser and server are encrypted (e.g. through HTTPS or WiFi encryption), according to researchers from Microsoft Research and Indiana University. Attempts to break a cryptosystem by deceiving or coercing people with legitimate access are not typically considered side-channel attacks: see social engineering and rubber-hose cryptanalysis. General classes of side-channel attack include: Cache attack – attacks based on attacker's ability to monitor cache accesses made by the victim in a shared physical system as in virtualized environment or a type of cloud service. Timing attack – attacks based on measuring how much time various computations (such as, say, comparing an attacker's given password with the victim's unknown one) take to perform. Power-monitoring attack – attacks that make use of varying power consumption by the hardware during computation. Electromagnetic attack – attacks based on leaked electromagnetic radiation, which can directly provide plaintexts and other information. Such measurements can be used to infer cryptographic keys using techniques equivalent to those in power analysis or can be used in non-cryptographic attacks, e.g. TEMPEST (aka Van Eck phreaking or radiation monitoring) attacks. Acoustic cryptanalysis – attacks that exploit sound produced during...
Text: Wikipédia, CC BY-SA 4.0. ·
Related cards
Cyberattack
Any attempt to expose, alter, disable, destroy, steal or gain unauthorized access to or make unauthorized use of a computer system
Nº Q4071928 ★★
Spectre (security vulnerability)
Security vulnerability in microprocessors performing branch prediction
Nº Q47037422 ★★
Cold boot attack
Means of compromising computer security by restarting the computer
Nº Q1584046 ★
Man-in-the-middle attack
Form of active eavesdropping in which the attacker makes connections with the victims and relays messages between them
Nº Q554830 ★★★
Padding oracle attack
Attack which uses the padding validation of a cryptographic message to decrypt the ciphertext
Nº Q7123320 ★
Cybercrime
Any crime that involves a computer and a network
Nº Q29137 ★★★