Published June 6, 2022 | Version v1

Exploiting Timing Side-Channel Leaks in Web Applications that Tell on Themselves

  • 1. imec-DistriNet, KU Leuven

Description

Abstract—The performance of remote timing attacks is highly dependent on the network connection that the attack is executed over, where jitter in both the up- and downstream direction can significantly deteriorate an attack’s performance. Traditional timing attacks overcome this problem by obtaining a large number of measurements. In this poster, we present a technique to remove the inaccuracies caused by downstream jitter in a remote timing attack, which we expect to reduce the number of measurements required to perform a successful timing attack. Our core idea is to exploit timestamps in HTTP responses, whose values are independent of the downstream jitter. To abuse these timestamps, the adversary synchronizes with the target web server’s clock edge, after which the observed timestamps allow the adversary to infer secret information. We present a method to synchronize with the server’s clock and discuss how to compensate for the clock drift between the attacker and target machines. To evaluate the feasibility of our technique, we also investigate the occurrence of timestamps in HTTP responses for the top 10,000 sites according to the Tranco list.

Notes

The poster was accepted at the 7th IEEE European Symposium on Security and Privacy (Euro S&P 2022) and presented in the poster session. Original poster: https://ieeeeurosp.github.io/2022/posters/

Files

eurosp22posters-final11-1-3.pdf

Files (184.1 kB)

Name Size Download all
md5:2389f72774d2e9b672d415e6e8953f08
184.1 kB Preview Download

Additional details

Related works

Is part of
Poster: 10.5281/zenodo.7068698 (DOI)