DUPEFS: Leaking Data Over the Network With Filesystem Deduplication Side Channels
Andrei Bacs, Saidgani Musaev, Kaveh Razavi, Cristiano Giuffrida, Herbert Bos
Abstract
To reduce the storage footprint with increasing data volumes, modern filesystems internally use deduplication to store a single copy of a data deduplication record, even if it is used by multiple files. Unfortunately, its implementation in today's advanced filesystems such as ZFS and Btrfs yields timing side channels that can reveal whether a chunk of data has been deduplicated. In this paper, we present the DUPEFS class of attacks to show that such side channels pose an unexpected security threat. In contrast to memory deduplication attacks, filesystem accesses are performed asynchronously to improve performance, which masks any potential signal due to deduplication. To complicate matters further, filesystem deduplication is often performed at large granularities, complicating high-entropy information leakage. To address these challenges, DUPEFS relies on carefully-crafted read/write operations that show exploitation is not only feasible, but that the signal can be amplified to mount byte-granular attacks over the network. We show attackers can leak sensitive data at the rate of ∼1.5 bytes per hour in a end-to-end remote attack, to leak a long-lived (critical) OAuth access token from the access log file of the nginx web server running on ZFS/HDD. Finally, we propose mitigations where read/write operations exhibit the same time-domain behavior, irrespective of the pre-existence of the data handled during the operation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1f689da5-d96c-4e76-88e3-ada704393788Cited by top-tier papers5
- InftyDedup: Scalable and Cost-Effective Cloud Tiering with DeduplicationIwona Kotlarska, Andrzej Jackowski, Krzysztof Lichota, Michal Welnicki et al.FAST 2023 · 23 citations
- Sync+Sync: A Covert Channel Built on fsync with StorageQisheng Jiang, Chundong WangUSENIX Security 2024 · 12 citations
- Attacks on Approximate Caches in Text-to-Image Diffusion ModelsDesen Sun, Shuncheng Jie, Sihang LiuUSENIX Security 2026 · 1 citation
- Pistis: A Decentralized Knowledge Graph Platform Enabling Ownership-Preserving SPARQL QueryingEnyuan Zhou, Song Guo, Zicong Hong, Christian S. Jensen et al.VLDB 2025 · 1 citation
- Side-Channel Attacks on Optane Persistent MemorySihang Liu, Suraaj Kanniwadi, Martin Schwarzl, Andreas Kogler et al.USENIX Security 2023
Builds on5
- ASLR on the Line: Practical Cache Attacks on the MMUBen Gras, Kaveh Razavi, Erik Bosman, Herbert Bos et al.NDSS 2017 · 276 citations
- Dedup Est Machina: Memory Deduplication as an Advanced Exploitation VectorErik Bosman, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaS&P 2016 · 252 citations
- Remote Memory-Deduplication AttacksMartin Schwarzl, Erik Kraft, Moritz Lipp, Daniel GrussNDSS 2022
- ABSynthe: Automatic Blackbox Side-channel Synthesis on Commodity MicroarchitecturesBen Gras, Cristiano Giuffrida, Michael Kurth, Herbert Bos et al.NDSS 2020
- A Tale of Two Headers: A Formal Analysis of Inconsistent Click-Jacking Protection on the WebStefano Calzavara, Sebastian Roth, Alvise Rabitti, Michael Backes et al.USENIX Security 2020
Related papers
- I know What You Sync: Covert and Side Channel Attacks on File Systems via syncfsCheng Gu, Yicheng Zhang, Nael B. Abu-GhazalehS&P 2025
- Page Cache AttacksDaniel Gruss, Erik Kraft, Trishita Tiwari, Michael Schwarz et al.CCS 2019 · 55 citations
- Practical Timing Side-Channel Attacks on Memory CompressionMartin Schwarzl, Pietro Borrello, Gururaj Saileshwar, Hanna Müller et al.S&P 2023
- Secret Spilling Drive: Leaking User Behavior through SSD ContentionJonas Juffinger, Fabian Rauscher, Giuseppe La Manna, Daniel GrussNDSS 2025
- Revisiting Frequency Analysis against Encrypted Deduplication via Statistical DistributionJingwei Li, Guoli Wei, Jiacheng Liang, Yanjing Ren et al.INFOCOM 2022 · 8 citations
