Exploiting Timing Side-Channel Leaks in Web Applications that Tell on Themselves
Authors/Creators
- 1. imec-DistriNet, KU Leuven
Description
Abstract—The performance of remote timing attacks is highly dependent on the network connection that the attack is executed over, where jitter in both the up- and downstream direction can significantly deteriorate an attack’s performance. Traditional timing attacks overcome this problem by obtaining a large number of measurements. In this poster, we present a technique to remove the inaccuracies caused by downstream jitter in a remote timing attack, which we expect to reduce the number of measurements required to perform a successful timing attack. Our core idea is to exploit timestamps in HTTP responses, whose values are independent of the downstream jitter. To abuse these timestamps, the adversary synchronizes with the target web server’s clock edge, after which the observed timestamps allow the adversary to infer secret information. We present a method to synchronize with the server’s clock and discuss how to compensate for the clock drift between the attacker and target machines. To evaluate the feasibility of our technique, we also investigate the occurrence of timestamps in HTTP responses for the top 10,000 sites according to the Tranco list.
Notes
Files
eurosp22posters-final11-1-3.pdf
Files
(184.1 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:2389f72774d2e9b672d415e6e8953f08
|
184.1 kB | Preview Download |
Additional details
Related works
- Is part of
- Poster: 10.5281/zenodo.7068698 (DOI)