Identifying Cross-origin Resource Status Using Application Cache

Identifying Cross-origin Resource Status Using Application Cache
复制标题

DOI:
10.14722/ndss.2015.23027
复制
发表时间:
2015-02
期刊:
--
影响因子:
--
通讯作者:
Sangho Lee;Hyungsub Kim;Jong Kim
Sangho Lee;Hyungsub Kim;Jong Kim
中科院分区:
其他
文献类型:
--
作者:
Sangho Lee;Hyungsub Kim;Jong Kim

文献摘要

被引文献

相似文献

HTML5应用程序缓存(AppCache)允许web应用程序在web浏览器的本地存储中缓存它们的同源和跨源资源,以便离线访问。然而,AppCache中的跨域资源缓存存在潜在的安全和隐私问题。在本文中,我们考虑了一种利用跨域AppCache的新型web隐私攻击。我们的攻击允许远程web攻击者利用受害web浏览器准确识别目标url的状态:存在、重定向或错误。特别是,我们的攻击可以在不使用客户端脚本的情况下执行,可以同时识别多个url的状态,并且可以准确识别目标url的重定向。我们进一步演示了利用基本攻击去匿名化和指纹受害者的高级攻击。首先,我们通过识别URL重定向或由于缺少或错误的登录信息而导致的错误来确定受害者web浏览器的登录状态。其次,我们通过识别URL存在来探测位于受害者web浏览器本地网络中的内部web服务器。我们还提出了有效的对策,以减轻所提出的攻击。
HTML5 Application Cache (AppCache) allows web applications to cache their same- and cross-origin resources in the local storage of a web browser to enable offline access. However, cross-origin resource caching in AppCache has potential security and privacy problems. In this paper, we consider a novel web privacy attack that exploits cross-origin AppCache. Our attack allows a remote web attacker to exploit a victim web browser to exactly identify the status of target URLs: existence, redirection, or error. Especially, our attack can be performed without using client-side scripts, can concurrently identify the status of multiple URLs, and can exactly identify the redirections of target URLs. We further demonstrate advanced attacks that leverage the basic attack to de-anonymize and fingerprint victims. First, we determine the login status of a victim web browser by identifying URL redirections or errors due to absent or erroneous login information. Second, we probe internal web servers located in the local network of a victim web browser by identifying URL existence. We also suggest an effective countermeasure to mitigate the proposed attacks.