Request and Conquer: Exposing Cross-Origin Resource Size

Request and Conquer: Exposing Cross-Origin Resource Size
复制标题

DOI:
--
复制
发表时间:
2016-08
期刊:
--
影响因子:
--
通讯作者:
Tom van Goethem;M. Vanhoef;Frank Piessens;W. Joosen
Tom van Goethem;M. Vanhoef;Frank Piessens;W. Joosen
中科院分区:
其他
文献类型:
--
作者:
Tom van Goethem;M. Vanhoef;Frank Piessens;W. Joosen

文献摘要

被引文献

相似文献

许多举措鼓励网站所有者为服务器和用户之间的通信启用和实施TLS加密。虽然这种加密在正确配置的情况下可以完全防止对手泄露流量的内容,但某些功能并没有被隐藏,最明显的是消息的大小。由于现代Web应用程序倾向于为用户提供针对他们委托这些Web服务的信息量身定制的视图,因此很明显,知道特定资源的大小,对手可以轻松地发现个人和敏感信息。在本文中,我们探讨了各种技术,可以用来揭示资源的大小。作为这种深入分析的结果,我们发现了浏览器存储机制中的几个设计缺陷,这些缺陷允许对手在几秒钟内暴露任何资源的确切大小。此外,我们报告了一种新的大小暴露技术对Wi-Fi网络。我们评估了攻击的严重性,并在多个现实世界的攻击场景中展示了其令人担忧的后果。此外,我们提出了一种改进的浏览器存储设计,并探索其他可行的解决方案,可以阻止大小暴露攻击。
Numerous initiatives are encouraging website owners to enable and enforce TLS encryption for the communication between the server and their users. Although this encryption, when configured properly, completely prevents adversaries from disclosing the content of the traffic, certain features are not concealed, most notably the size of messages. As modern-day web applications tend to provide users with a view that is tailored to the information they entrust these web services with, it is clear that knowing the size of specific resources, an adversary can easily uncover personal and sensitive information. In this paper, we explore various techniques that can be employed to reveal the size of resources. As a result of this in-depth analysis, we discover several design flaws in the storage mechanisms of browsers, which allows an adversary to expose the exact size of any resource in mere seconds. Furthermore, we report on a novel size-exposing technique against Wi-Fi networks. We evaluate the severity of our attacks, and show their worrying consequences in multiple real-world attack scenarios. Furthermore, we propose an improved design for browser storage, and explore other viable solutions that can thwart size-exposing attacks.