Leakuidator: Leaky Resource Attacks and Countermeasures

Leakuidator: Leaky Resource Attacks and Countermeasures
复制标题

Leakuidator:泄漏资源攻击及对策

DOI:
10.1007/978-3-030-90022-9_8
复制
发表时间:
2021
期刊:
International Conference on Security and Privacy in Communication Systems
影响因子:
--
通讯作者:
Reza Curtmola
Reza Curtmola
中科院分区:
--
文献类型:
--
作者:
Mojtaba Zaheri;Reza Curtmola

文献摘要

参考文献

相似文献

泄密资源攻击利用资源共享服务的流行在网络上进行有针对性的去匿名化。它们易于执行,因为由于在安全性和功能性之间进行权衡,许多资源共享服务天生就容易受到攻击。尽管前人的工作表明这种攻击会导致严重的隐私威胁,但防御这种威胁在很大程度上仍然是一个没有得到解决的领域。在这项工作中,我们从攻击有效性和攻击缓解两个方面对泄漏资源攻击的最新进展进行了介绍。我们首先展示了可在更广泛的浏览器上运行的可靠攻击实现,并通过识别攻击的新变体,首先展示了泄漏资源攻击具有比之前认为的更大的攻击面。然后,我们提出了Leakuidator,这是第一个可以立即部署的客户端防御,无需浏览器供应商和网站所有者的认可。在较高级别上,泄密计算器识别在呈现网页时做出的潜在可疑请求,并且针对每个这样的请求:(1)通过首先从请求中移除cookie来呈现请求,以及(2)发起与原始请求相同的第二个请求(即,包含被移除的cookie),但不呈现其响应。这一额外的请求保持了与现有Web功能的兼容性,例如分析和跟踪服务。我们已经将Leakuidator实现为三种基于Chromium的浏览器的浏览器扩展。实验结果表明,Leakuidator引入的开销很小,因此对用户体验的影响很小。该扩展还包括可用性旋钮,允许用户重复使用过去的选择,并调整识别潜在可疑请求的标准的严格程度。
Leaky resource attacks leverage the popularity of resource-sharing services to conduct targeted deanonymization on the web. They are simple to execute because many resource-sharing services are inherently vulnerable due to the trade-offs made between security and functionality. Even though previous work has shown that such attacks can lead to serious privacy threats, defending against this threat is an area that has remained largely unaddressed.In this work, we advance the state of the art on leaky resource attacks on both attack effectiveness and attack mitigation fronts. We first show that leaky resource attacks have a larger attack surface than what was previously believed, by showing reliable attack implementations that work across a broader range of browsers and by identifying new variants of the attack. We then proposeLeakuidator, the first client-side defense that can be deployed right away, without buy-in from browser vendors and website owners. At a high level,Leakuidatoridentifies potentially suspicious requests made when a webpage is rendered and for each such request: (1) renders the request by first removing cookies from it, and (2) initiates a second request that is identical with the original request (i.e., contains the cookies that were removed), but does not render its response. This additional request maintains compatibility with existing web functionality, such as analytics and tracking services. We have implementedLeakuidatoras a browser extension for three Chromium-based browsers. Experimental results show thatLeakuidatorintroduces a small overhead and thus the impact on user experience is minimal. The extension also includes usability knobs, allowing users to reuse past choices and to adjust how strict is the criteria for identifying potentially suspicious requests.
动态安全监视器的动态内联
DOI: 10.1007/978-3-642-15257-3_16
发表时间: 2010
期刊: Comput. Secur.
影响因子: --
作者:
Jonas Magazinius;Alejandro Russo;A. Sabelfeld
通讯作者: A. Sabelfeld
DOI: 10.14722/ndss.2015.23295
发表时间: 2015
期刊: --
影响因子: --
作者:
Lujo Bauer;Shaoying Cai;Limin Jia;Timothy Passaro;Michael Stroucken;Yuan Tian
通讯作者: Lujo Bauer;Shaoying Cai;Limin Jia;Timothy Passaro;Michael Stroucken;Yuan Tian
唤醒网络中的潜伏特工:滥用 Service Worker 造成隐私泄露
DOI: 10.14722/ndss.2021.23104
发表时间: 2021
期刊: Network and Distributed System Security Symposium
影响因子: --
作者:
Karami, Soroush;Ilia, Panagiotis;Polakis, Jason
通讯作者: Polakis, Jason
Web 浏览器中事件处理和 DOM 的信息流控制
DOI: 10.1109/csf.2015.32
发表时间: 2015
期刊: 2015 IEEE 28th Computer Security Foundations Symposium
影响因子: --
作者:
Vineet Rajani;Abhishek Bichhawat;D. Garg;Christian Hammer
通讯作者: Christian Hammer
无脚本攻击:不碰门槛就偷更多馅饼
DOI: 10.3233/jcs-130494
发表时间: 2014
期刊: J. Comput. Secur.
影响因子: --
作者:
M. Heiderich;Marcus Niemietz;Felix Schuster;Thorsten Holz;Jörg Schwenk
通讯作者: Jörg Schwenk