Clock Around the Clock: Time-Based Device Fingerprinting

Clock Around the Clock: Time-Based Device Fingerprinting
复制标题

DOI:
10.1145/3243734.3243796
复制
发表时间:
2018-10
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Iskander Sánchez-Rola;Igor Santos;D. Balzarotti
Iskander Sánchez-Rola;Igor Santos;D. Balzarotti
中科院分区:
其他
文献类型:
--
作者:
Iskander Sánchez-Rola;Igor Santos;D. Balzarotti

文献摘要

被引文献

相似文献

物理设备指纹识别利用硬件特性来唯一地标识一台机器。该技术已用于身份验证、许可证绑定或攻击者识别等任务。最近,硬件功能也被引入到识别网络用户和执行网络跟踪。一种特殊类型的硬件指纹利用了计算机内部时钟信号的差异。但是,以前测试这些差异的方法依赖于在目标机器上运行本机代码执行的复杂实验。在本文中,我们展示了一种计算硬件指纹的新方法,该方法基于对API函数中现成的指令序列的执行时序。由于它的简单性,这个方法也可以通过简单地计时几行看似无害的JavaScript代码来远程执行。我们用不同的函数(如常见的字符串操作或广泛的加密例程)测试了我们的方法,并发现其中一些可以用作指纹识别的基本块。使用这种技术,我们实现了一个名为CryptoFP的工具。我们在一个同构场景中测试了它的原生实现,以区分一组完全相同的计算机(包括软件和硬件)。在这个场景中,CryptoFP能够正确区分所有相同的计算机,并在不同的CPU负载配置下识别同一台计算机,优于其他所有硬件指纹识别方法。然后,我们展示了如何使用HTML5加密API和web设备指纹的标准定时API的组合来实现CryptoFP。在这种情况下,我们将我们的方法与其他最先进的web设备指纹识别解决方案进行了比较,这两种方法都是在相同的同构场景中进行的,并通过对运行异构设备的真实用户进行实验。在这两种情况下,我们的方法明显优于所有现有的方法。
Physical device fingerprinting exploits hardware features to uniquely identify a machine. This technique has been used for authentication, license binding, or attackers identification, among other tasks. More recently, hardware features have also been introduced to identify web users and perform web tracking. A particular type of hardware fingerprint exploits differences in the computer internal clock signals. However, previous methods to test for these differences relied on complex experiments performed by running native code in the target machine. In this paper, we show a new way to compute a hardware finger- printing, based on timing the execution of sequences of instructions readily available in API functions. Due to its simplicity, this method can also be performed remotely by simply timing few seemingly innocuous lines of JavaScript code. We tested our approach with different functions, such as common string manipulation or widespread cryptographic routines, and found that several of them can be used as basic blocks for fingerprinting. Using this technique, we implemented a tool called CryptoFP. We tested its native implementation in a homogeneous scenario, to distinguish among a perfectly identical (both in software and hardware) set of computers. CryptoFP was able to correctly discriminate all the identical computers in this scenario and recognize the same computer also under different CPU load configurations, outperforming every other hardware fingerprinting method. We then show how CryptoFP can be implemented using a combination of the HTML5 Cryptography API and standard timing API for web device fingerprinting. In this case, we compared our method, both in the same homogeneous scenario and by performing an experiment with real-world users running heterogeneous devices, against other state-of-the-art web device fingerprinting solutions. In both cases, our approach clearly outperforms all existing methods.