Leakuidator: Leaky Resource Attacks and Countermeasures
Leakuidator: Leaky Resource Attacks and Countermeasures
复制标题
Leakuidator:泄漏资源攻击及对策
DOI:
10.1007/978-3-030-90022-9_8
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
Reza Curtmola
中科院分区:
文献类型:
--
作者:
Mojtaba Zaheri;Reza Curtmola
Leaky resource attacks leverage the popularity of resource-sharing services to conduct targeted deanonymization on the web. They are simple to execute because many resource-sharing services are inherently vulnerable due to the trade-offs made between security and functionality. Even though previous work has shown that such attacks can lead to serious privacy threats, defending against this threat is an area that has remained largely unaddressed.In this work, we advance the state of the art on leaky resource attacks on both attack effectiveness and attack mitigation fronts. We first show that leaky resource attacks have a larger attack surface than what was previously believed, by showing reliable attack implementations that work across a broader range of browsers and by identifying new variants of the attack. We then proposeLeakuidator, the first client-side defense that can be deployed right away, without buy-in from browser vendors and website owners. At a high level,Leakuidatoridentifies potentially suspicious requests made when a webpage is rendered and for each such request: (1) renders the request by first removing cookies from it, and (2) initiates a second request that is identical with the original request (i.e., contains the cookies that were removed), but does not render its response. This additional request maintains compatibility with existing web functionality, such as analytics and tracking services. We have implementedLeakuidatoras a browser extension for three Chromium-based browsers. Experimental results show thatLeakuidatorintroduces a small overhead and thus the impact on user experience is minimal. The extension also includes usability knobs, allowing users to reuse past choices and to adjust how strict is the criteria for identifying potentially suspicious requests.
登录
查看更多内容
DOI:
10.1007/978-3-642-15257-3_16
发表时间:
2010
期刊:
Comput. Secur.
影响因子:
--
作者:
Jonas Magazinius;Alejandro Russo;A. Sabelfeld
通讯作者:
A. Sabelfeld
DOI:
10.14722/ndss.2015.23295
发表时间:
2015
期刊:
--
影响因子:
--
作者:
Lujo Bauer;Shaoying Cai;Limin Jia;Timothy Passaro;Michael Stroucken;Yuan Tian
通讯作者:
Lujo Bauer;Shaoying Cai;Limin Jia;Timothy Passaro;Michael Stroucken;Yuan Tian
DOI:
10.14722/ndss.2021.23104
发表时间:
2021
期刊:
Network and Distributed System Security Symposium
影响因子:
--
作者:
Karami, Soroush;Ilia, Panagiotis;Polakis, Jason
通讯作者:
Polakis, Jason
DOI:
10.1109/csf.2015.32
发表时间:
2015
期刊:
2015 IEEE 28th Computer Security Foundations Symposium
影响因子:
--
作者:
Vineet Rajani;Abhishek Bichhawat;D. Garg;Christian Hammer
通讯作者:
Christian Hammer
DOI:
10.3233/jcs-130494
发表时间:
2014
期刊:
J. Comput. Secur.
影响因子:
--
作者:
M. Heiderich;Marcus Niemietz;Felix Schuster;Thorsten Holz;Jörg Schwenk
通讯作者:
Jörg Schwenk