Prime+Probe 1, JavaScript 0: Overcoming Browser-based Side-Channel Defenses

Prime+Probe 1, JavaScript 0: Overcoming Browser-based Side-Channel Defenses
复制标题

DOI:
--
复制
发表时间:
2021-03
影响因子:
6.8
通讯作者:
A. Shusterman;Ayush Agarwal;Sioli O'Connell;Daniel Genkin;Yossef Oren;Y. Yarom
A. Shusterman;Ayush Agarwal;Sioli O'Connell;Daniel Genkin;Yossef Oren;Y. Yarom
中科院分区:
计算机科学1区
文献类型:
--
作者:
A. Shusterman;Ayush Agarwal;Sioli O'Connell;Daniel Genkin;Yossef Oren;Y. Yarom

文献摘要

被引文献

相似文献

“缓存中的永恒战争”已经到达浏览器,多种基于缓存的侧通道攻击和对策正在提出。一种常见的对策是禁用或限制被认为对执行攻击至关重要的JavaScript功能。为了评估这种方法的有效性,在这项工作中,我们试图确定这些JavaScript的功能是必不可少的进行基于缓存的攻击。我们开发了一系列的攻击,逐步减少依赖于JavaScript功能,最终在第一个基于浏览器的侧通道攻击,完全从级联样式表(CSS)和HTML构建,即使脚本执行被完全阻止。然后,我们表明,避免JavaScript功能使我们的技术在架构上不可知,导致微架构的网站指纹攻击,跨硬件平台,包括英特尔酷睿,AMD锐龙,三星Exynos和苹果M1架构。作为最后的贡献,我们在强化的浏览器环境中评估了我们的技术,包括Tor浏览器,Deter-Fox(Cao等人,CCS 2017)和Chrome Zero(Schwartz等人,NDSS 2018)。我们确认,这些方法都不能完全抵御我们的攻击。我们进一步认为,Chrome Zero的保护需要更全面地应用,如果采取这种方法,Chrome Zero的性能和用户体验将严重下降。
The "eternal war in cache" has reached browsers, with multiple cache-based side-channel attacks and countermeasures being suggested. A common approach for countermeasures is to disable or restrict JavaScript features deemed essential for carrying out attacks. To assess the effectiveness of this approach, in this work we seek to identify those JavaScript features which are essential for carrying out a cache-based attack. We develop a sequence of attacks with progressively decreasing dependency on JavaScript features, culminating in the first browser-based side-channel attack which is constructed entirely from Cascading Style Sheets (CSS) and HTML, and works even when script execution is completely blocked. We then show that avoiding JavaScript features makes our techniques architecturally agnostic, resulting in microarchitectural website fingerprinting attacks that work across hardware platforms including Intel Core, AMD Ryzen, Samsung Exynos, and Apple M1 architectures. As a final contribution, we evaluate our techniques in hardened browser environments including the Tor browser, Deter-Fox (Cao el al., CCS 2017), and Chrome Zero (Schwartz et al., NDSS 2018). We confirm that none of these approaches completely defend against our attacks. We further argue that the protections of Chrome Zero need to be more comprehensively applied, and that the performance and user experience of Chrome Zero will be severely degraded if this approach is taken.