Inferring browser activity and status through remote monitoring of storage usage

Inferring browser activity and status through remote monitoring of storage usage
复制标题

通过远程监控存储使用情况推断浏览器活动和状态

DOI:
--
复制
发表时间:
2016
期刊:
Asia-Pacific Computer Systems Architecture Conference
影响因子:
--
通讯作者:
Jong Kim
Jong Kim
中科院分区:
--
文献类型:
--
作者:
Hyungsub Kim;Sangho Lee;Jong Kim

文献摘要

被引文献

相似文献

Web应用程序使用Web浏览器的本地存储来临时存储用于缓存的静态资源,并持久存储用于有状态服务的个性化数据。由于不同的Web应用程序在大小和时间方面使用不同的本地存储,攻击者可以推断用户的浏览器活动和状态,如果他们可以监视存储使用情况:例如,用户正在查看哪个网站以及用户是否登录到某个网站。在本文中,我们将探讨被动和主动的Web攻击,利用网络管理API从Web浏览器中提取这些信息,因为API允许我们不断监控可用存储空间的大小。我们开发了两种网络攻击:跨标签活动推断攻击被动地监视用户当前正在访问哪个网站,浏览器状态推断攻击主动地识别浏览器状态,例如浏览器历史记录和登录信息。我们的攻击成功地从运行在各种平台上的Chrome中窃取私人信息,准确率达到90%以上。我们进一步提出了一个有效的解决方案,对攻击。
Web applications use the local storage of a web browser to temporarily store static resources for caching and persistently store personalized data for stateful services. Since different web applications use the local storage differently in terms of size and time, attackers can infer a user's browser activity and status if they can monitor storage usage: for example, which web site a user is viewing and whether a user has logged in to a certain web site. In this paper, we explore passive and active web attacks that exploit the Quota Management API to extract such information from a web browser, as the API allows us to continuously monitor the size of available storage space. We develop two web attacks: a cross-tab activity inference attack to passively monitor which web site a user is currently visiting and a browser status inference attack to actively identify the browser status such as browser history and login information. Our attacks are successful at stealing private information from Chrome running on various platforms with ∼90% accuracy. We further propose an effective solution against the attacks.