首页> 外文OA文献 >Request and conquer: exposing cross-origin resource size
【2h】

Request and conquer: exposing cross-origin resource size

机译:请求和征服:公开跨域资源的大小

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Numerous initiatives are encouraging website owners to enable and enforce TLS encryption for the communication between the server and their users. Although this encryption, when configured properly, completely prevents adversaries from disclosing the content of the traffic, certain features are not concealed, most notably the size of messages. As modern-day web applications tend to provide users with a view that is tailored to the information they entrust these web services with, it is clear that knowing the size of specific resources, an adversary can easily uncover personal and sensitive information.In this paper, we explore various techniques that can be employed to reveal the size of resources. As a result of this in-depth analysis, we discover several design flaws in the storage mechanisms of browsers, which allows an adversary to expose the exact size of any resource in mere seconds. Furthermore, we report on a novel size-exposing technique against Wi-Fi networks. We evaluate the severity of our attacks, and show their worrying consequences in multiple real-world attack scenarios. Furthermore, we propose an improved design for browser storage, and explore other viable solutions that can thwart size-exposing attacks.
机译:许多举措都在鼓励网站所有者为服务器与其用户之间的通信启用并实施TLS加密。尽管这种加密在配置正确时可以完全防止对手泄露流量的内容,但是某些功能并未被隐藏,最显着的是消息的大小。由于现代Web应用程序倾向于为用户提供适合于他们委托这些Web服务的信息的视图,因此很明显,知道特定资源的大小后,攻击者就可以轻松发现个人和敏感信息。 ,我们探索了可以用来揭示资源规模的各种技术。这项深入分析的结果是,我们发现了浏览器存储机制中的一些设计缺陷,这使对手可以在几秒钟内暴露出任何资源的确切大小。此外,我们报告了针对Wi-Fi网络的一种新颖的尺寸曝光技术。我们评估攻击的严重性,并在多种实际攻击场景中显示它们令人担忧的后果。此外,我们提出了一种用于浏览器存储的改进设计,并探索了其他可以阻止暴露于大小的攻击的可行解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号