Practical Covert Channel Across Isolated Browser Instances via GPU Command Queue Contention
Jinhong Liu, Zifeng Kang, Song Li, Yinzhi Cao
Abstract
Web storages, e.g., cookies, are isolated across different browser modes (e.g., normal vs. incognito) and browsers (e.g., Chrome vs. Safari) to ensure user privacy. Despite such browser-level isolation, researchers have found covert communication channels between different modes and browsers, which can break such a security mechanism. However, existing covert communications are impractical and unreliable in the real world scenarios, where noise is prevalent. Furthermore, multiple prior covert channels only support cross-mode-not cross-browser-communications, because the relevant resources are shared within a single browser. In this paper, we discover a novel covert channel due to GPU command queue contention and then design a framework, called , for both cross-mode and cross-browser covert communication. negotiates an adaptive communication speed between the sender and the receiver and then facilitates the covert communication. We evaluated in real-world settings by deploying it to crowd-sourced workers on Amazon Mechanical Turk, simply asking them to visit two websites without imposing additional constraints. Our evaluation shows that covert communication achieves a 100 % accuracy once the data transmission is completed, with an overall completion rate of 92.81 % across 1,434 AMT experiments. So far, Firefox, Safari and Tor developers have confirmed our attack and are working with us on practical defenses.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4f0ba57c-a92e-4539-bb86-058f6e50fed2Builds on25
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim et al.USENIX Security 2017 · 536 citations
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz et al.USENIX Security 2016 · 500 citations
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice et al.USENIX Security 2016 · 451 citations
- Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser FingerprintsPierre Laperdrix, Walter Rudametkin, Benoit BaudryS&P 2016 · 279 citations
- Rendered Insecure: GPU Side Channel Attacks are PracticalHoda Naghibijouybari, Ajaya Neupane, Zhiyun Qian, Nael B. Abu-GhazalehCCS 2018 · 214 citations
Related papers
- Rendering Contention Channel Made Practical in Web BrowsersShujiang Wu, Jianjia Yu, Min Yang, Yinzhi CaoUSENIX Security 2022
- Pool-Party: Exploiting Browser Resource Pools for Web TrackingPeter Snyder, Soroush Karami, Arthur Edelstein, Benjamin Livshits et al.USENIX Security 2023
- The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the WebJannis Rautenstrauch, Giancarlo Pellegrino, Ben StockS&P 2023
- EmPoWeb: Empowering Web Applications with Browser ExtensionsDolière Francis SoméS&P 2019 · 60 citations
- Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie PoliciesGertjan Franken, Tom van Goethem, Wouter JoosenUSENIX Security 2018 · 39 citations
