【24h】

Depending on HTTP/2 for Privacy? Good Luck!

机译:取决于HTTP / 2的隐私权?祝好运!

获取原文

摘要

The new multi-threaded server operation feature in HTTP/2 results in multiplexed object transmission. This obfuscates the sizes of the encrypted objects, based on which passive network eavesdroppers inferred sensitive information. Therefore, recent works speculate that HTTP/2 can have an unanticipated positive effect on communication privacy in addition to the privacy provided by TLS/SSL. Orthogonal to these works, we show that it is possible for an on-path passive eavesdropper to completely break the privacy offered by the schemes that leverage HTTP/2 multiplexing. Our adversary works based on the following intuition: restricting only one HTTP/2 object to be in the server queue at any point of time will eliminate multiplexing of that object and any privacy benefit thereof. Our adversary achieves this by altering network parameters such as jitter, bandwidth and packet drop rate to ensure that no new client request reaches the server while it is serving a previously requested object. Our adversary was able to break the privacy of a real-world HTTP/2 website 90% of the time. To the best of our knowledge, this is the first privacy attack on HTTP/2.
机译:HTTP / 2中新的多线程服务器操作功能导致多路对象传输。这模糊了加密对象的大小,基于哪个被动网络窃听者推断出敏感信息。因此,最近的工作推测HTTP / 2除了可以提供TLS / SSL提供的隐私之外,还可以对通信隐私产生意外的积极影响。与这些工作正交的是,我们表明,路径上的被动窃听者有可能完全破坏利用HTTP / 2复用的方案所提供的隐私。我们的对手基于以下直觉进行工作:在任何时间点仅将一个HTTP / 2对象限制在服务器队列中,将消除该对象的多路复用及其任何隐私利益。我们的对手通过更改网络参数(例如抖动,带宽和数据包丢失率)来实现此目的,以确保在服务于先前请求的对象时,不会有新的客户端请求到达服务器。我们的对手有90%的时间能够破坏真实HTTP / 2网站的隐私。据我们所知,这是对HTTP / 2的首次隐私攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号