Back to search

University of Illinois at Urbana-Champaign

Attacking schedule indistinguishability in real-time systems

Abstract

dc:description

Real-Time Systems (RTS) have gained prominence in new domains such as autonomous cars, drones, and the Internet-of-Things (IoT). RTS have stringent timing requirements for ensuring their correct operation. Such requirements make it necessary for systems to be deterministic at run-time. This determinism can be used against them as an attack surface, like scheduler side-channels. One way to reduce determinism in systems is by adding noise to system components in order to disrupt their deterministic behavior. Schedule indistinguishability, that is inspired by differential privacy, protects RTS by increasing the indistinguishability of the schedule. It introduces the notion of ϵ-indistinguishability, that measures the probability of information leakage when system schedules are observed. Implemented in an ϵ-Scheduler, it is able to not only offer a higher degree of protection, but also do so with actual guarantees while still maintaining a high degree of performance. The efficacy of the ϵ-Scheduler is epitomized by its success in thwarting an identification attack on a real-time video streaming application. However, schedule indistinguishability can be compromised by side-channels, that leak critical information representative of the private timing data. This information can be combined with other observations made by an adversary to launch attacks on schedule indistinguishability. The scope of attacks using side-channels is explored in this thesis. Two attacks, namely, a timing-based attack and a privacy budget attack are presented. While the timing-based attack takes advantage of the time taken to draw a sample from the noise distribution, the privacy budget attack uses the value of the protection duration. After detailing their threat models and showing their success in disrupting schedule indistinguishability, the thesis investigates their effectiveness in causing security breaches in RTS. The evaluations are carried out using the aforementioned identification attack on the video streaming application. Our results show that side-channel attacks can break schedule indistinguishability and, in turn, undermine the security of RTS against scheduler side-channels. The work can be divided into three key steps: 1. Ascertain the type of information that can be leaked by systems implementing the ϵ-Scheduler. 2. Determine the scope of side-channel attacks using the leaked information. 3. Analyze the relationship between schedule indistinguishability and security of RTS.

Degree

thesis:*
Name thesis:degree_name
M.S.
Level thesis:degree_level
Thesis
Discipline thesis:degree_discipline
Computer Science
Grantor
University of Illinois at Urbana-Champaign
Year dc:date
2022

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Sanyal, Debopam
Contributors dc:contributor
  • Mohan, Sibin

Subjects

dc:subject × 3

Rights

dc:rights
Statement dc:rights
  • Copyright 2022 Debopam Sanyal
Language dc:language
en, eng

Identifiers

dc:identifier.*
Handle dc:identifier
https://hdl.handle.net/2142/115429

Chain of custody

source
Harvested from
University of Illinois - Urbana-Champaign
Base URL
www.ideals.illinois.edu/oai-pmh
Last updated
2026-07-22
Source record
OAI-PMH GetRecord
citation

Sanyal, Debopam. Attacking schedule indistinguishability in real-time systems. Thesis thesis, University of Illinois at Urbana-Champaign, 2022. https://hdl.handle.net/2142/115429