DBREACH: Stealing from Databases Using Compression Side Channels
Mathew Hogan, Yan Michalevsky, Saba Eskandarian
Abstract
We introduce new compression side-channel attacks against database storage engines that simultaneously support compression of database pages and encryption at rest. Given only limited, indirect access to an encrypted and compressed database table, our attacks extract arbitrary plaintext with high accuracy. We demonstrate accurate and performant attacks on the InnoDB storage engine variants found in MariaDB and MySQL as well as the WiredTiger storage engine for MongoDB.Our attacks overcome obstacles unique to the database setting that render previous techniques developed to attack TLS ineffective. Unlike the web setting, where the exact length of a compressed and encrypted message can be observed, we make use of only approximate ciphertext size information gleaned from file sizes on disk. We amplify this noisy signal and combine it with new attack heuristics tailored to the database setting to extract secret plaintext. Our attacks can detect whether a random string appears in a table with > 90% accuracy and extract 10-character random strings from encrypted tables with > 95% success.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2219dbaa-1948-4b05-81d6-c1637c12ddbaCited by top-tier papers9
- GPU.zip: On the Side-Channel Implications of Hardware-Based Graphical Data CompressionYingchen Wang, Riccardo Paccagnella, Zhao Gang, Willy R. Vasquez et al.S&P 2024 · 17 citations
- Injection Attacks Against End-to-End Encrypted ApplicationsAndrés Fábrega, Carolina Ortega Pérez, Armin Namavari, Ben Nassi et al.S&P 2024 · 9 citations
- Exploiting Leakage in Password Managers via Injection AttacksAndrés Fábrega, Armin Namavari, Rachit Agarwal, Ben Nassi et al.USENIX Security 2024 · 1 citation
- Leafblower: a Leakage Attack Against Tee-Based Encrypted DatabasesZachary Espiritu, Seny Kamara, Tarik Moataz, Valentin OgierS&P 2026 · 1 citation
- Side-Channel Attacks on Open vSwitchDaewoo Kim, Sihang LiuUSENIX Security 2026 · 1 citation
Builds on3
- Request and Conquer: Exposing Cross-Origin Resource SizeTom van Goethem, Mathy Vanhoef, Frank Piessens, Wouter JoosenUSENIX Security 2016 · 35 citations
- Safecracker: Leaking Secrets through Compressed CachesPo-An Tsai, Andrés Sánchez, Christopher W. Fletcher, Daniel SánchezASPLOS 2020 · 23 citations
- Practical Timing Side-Channel Attacks on Memory CompressionMartin Schwarzl, Pietro Borrello, Gururaj Saileshwar, Hanna Müller et al.S&P 2023
Related papers
- Criminology: Refined Techniques for Compression Side-Channel AttacksYuanming Song, Lenka Mareková, Kenneth G. PatersonCCS 2026
- Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed ChannelsFabian Bäumer, Marcus BrinkmannCCS 2026
- CacheQL: Quantifying and Localizing Cache Side-Channel Vulnerabilities in Production SoftwareYuanyuan Yuan, Zhibo Liu, Shuai WangUSENIX Security 2023
- Remote Memory-Deduplication AttacksMartin Schwarzl, Erik Kraft, Moritz Lipp, Daniel GrussNDSS 2022
- Page Cache AttacksDaniel Gruss, Erik Kraft, Trishita Tiwari, Michael Schwarz et al.CCS 2019 · 55 citations
