Chetan Jaiswal of Quinnipiac University explains what a side-channel attack is and how it impacts modern cybersecurity.
When people hear the word cyberattack, they usually imagine someone guessing a password, planting malware, stealing a computer, hacking an organisation’s network or exploiting a flaw in software. A side-channel attack works differently. It looks for clues a computer gives away while doing ordinary work.
A simple analogy is a locked safe. A thief may not know the combination and may not be able to break the lock. But if the thief can listen closely as the dial turns, small clicks or churns or pauses might reveal something about what is happening inside. The safe is not meant to share that information, but its physical behaviour still leaks clues.
Modern computers have their own versions of such clues. For example, each computer might take different amounts of time to complete different tasks or may use different amounts of electricity. The hardware – processors, memory, graphics cards and storage drives – may leave tiny patterns as they work.
I’m a computer scientist who studies security and privacy. I define a side-channel attack as an attempt to observe these indirect clues and use them to infer something private.











