首页> 外文OA文献 >The clock is still ticking: Timing attacks in the modern web
【2h】

The clock is still ticking: Timing attacks in the modern web

机译:时间仍在滴答滴答:现代网络中的定时攻击

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Web-based timing attacks have been known for over a decade, and it has been shown that, under optimal network conditions, an adversary can use such an attack to obtain information on the state of a user in a cross-origin website. In recent years, desktop computers have given way to laptops and mobile devices, which are mostly connected over a wireless or mobile network. These connections often do not meet the optimal conditions that are required to reliably perform cross-site timing attacks.In this paper, we show that modern browsers expose new side-channels that can be used to acquire accurate timing measurements, regardless of network conditions. Using several real-world examples, we introduce four novel web-based timing attacks against modern browsers and describe how an attacker can use them to obtain personal information based on a user's state on a cross-origin website. We evaluate our proposed attacks and demonstrate that they significantly outperform current attacks in terms of speed, reliability, and accuracy. Furthermore, we show that the nature of our attacks renders traditional defenses, i.e., those based on randomly delaying responses, moot and discuss possible server-side defense mechanisms.
机译:基于Web的定时攻击已经有十多年的历史了,并且已经证明,在最佳网络条件下,攻击者可以使用这种攻击来获取有关跨域网站中用户状态的信息。近年来,台式计算机已经让位于笔记本电脑和移动设备,而笔记本电脑和移动设备大多通过无线或移动网络连接。这些连接通常不满足可靠地执行跨站点定时攻击所需的最佳条件。在本文中,我们证明了现代浏览器会暴露新的侧信道,而无论网络条件如何,这些侧信道均可用于获取准确的定时测量。通过使用几个真实的示例,我们介绍了针对现代浏览器的四种新颖的基于Web的定时攻击,并描述了攻击者如何根据跨站点网站上的用户状态使用它们来获取个人信息。我们评估了我们提出的攻击,并证明了它们在速度,可靠性和准确性方面均明显优于当前攻击。此外,我们表明攻击的性质提供了传统的防御,即基于随机延迟响应的防御,讨论并讨论了可能的服务器端防御机制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号