USENIX Security2020Top-tier venue
Timeless Timing Attacks: Exploiting Concurrency to Leak Secrets over Remote Connections
Tom van Goethem, Christina Pöpper, Wouter Joosen, Mathy Vanhoef
Abstract
To perform successful remote timing attacks, an adversary typically collects a series of network timing measurements and subsequently performs statistical analysis to reveal a difference in execution time. The number of measurements that must be obtained largely depends on the amount of jitter that the requests and responses are subjected to. In remote timing attacks, a significant source of jitter is the network path between the adversary and the targeted server, making it practically infeasible to successfully exploit timing side-channels that exhibit only a small difference in execution time. In this paper, we introduce a conceptually novel type of timing attack that leverages the coalescing of packets by network protocols and concurrent handling of requests by applications. These concurrency-based timing attacks infer a relative timing difference by analyzing the order in which responses are returned, and thus do not rely on any absolute timing information. We show how these attacks result in a 100-fold improvement over typical timing attacks performed over the Internet, and can accurately detect timing differences as small as 100ns, similar to attacks launched on a local system. We describe how these timing attacks can be successfully deployed against HTTP/2 webservers, Tor onion services, and EAP-pwd, a popular Wi-Fi authentication method.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers18
- Are We There Yet? Timing and Floating-Point Attacks on Differential Privacy SystemsJiankai Jin, Eleanor McMurtry, Benjamin I. P. Rubinstein, Olga OhrimenkoS&P 2022 · 57 citations
- XSinator.com: From a Formal Model to the Automatic Evaluation of Cross-Site Leaks in Web BrowsersLukas Knittel, Christian Mainka, Marcus Niemietz, Dominik Trevor Noß et al.CCS 2021 · 11 citations
- RLS Side Channels: Investigating Leakage of Row-Level Security Protected Data Through Query Execution TimeChen Dar, Moshik Hershcovitch, Adam MorrisonSIGMOD 2023 · 6 citations
- Cross-Core Interrupt Detection: Exploiting User and Virtualized IPIsFabian Rauscher, Daniel GrussCCS 2024 · 4 citations
- SnailLoad: Exploiting Remote Network Latency Measurements without JavaScriptStefan Gast, Roland Czerny, Jonas Juffinger, Fabian Rauscher et al.USENIX Security 2024 · 4 citations
Builds on6
- Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwdMathy Vanhoef, Eyal RonenS&P 2020 · 146 citations
- Clock Around the Clock: Time-Based Device FingerprintingIskander Sánchez-Rola, Igor Santos, Davide BalzarottiCCS 2018 · 91 citations
- Trusted Browsers for Uncertain TimesDavid Kohlbrenner, Hovav ShachamUSENIX Security 2016 · 83 citations
- Loophole: Timing Attacks on Shared Event Loops in ChromePepe Vila, Boris KöpfUSENIX Security 2017 · 66 citations
- Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie PoliciesGertjan Franken, Tom van Goethem, Wouter JoosenUSENIX Security 2018 · 39 citations
Related papers
- Time and Time Again: Leveraging TCP Timestamps to Improve Remote Timing AttacksVik Vanderlinden, Tom van Goethem, Mathy VanhoefNDSS 2026
- Off-Path TCP Exploit: How Wireless Routers Can Jeopardize Your SecretsWeiteng Chen, Zhiyun QianUSENIX Security 2018 · 35 citations
- Off-Path TCP Hijacking in Wi-Fi Networks: A Packet-Size Side Channel AttackZiqiang Wang, Xuewei Feng, Qi Li, Kun Sun et al.NDSS 2025
- Exploiting Sequence Number Leakage: TCP Hijacking in NAT-Enabled Wi-Fi NetworksYuxiang Yang, Xuewei Feng, Qi Li, Kun Sun et al.NDSS 2024
- Page Cache AttacksDaniel Gruss, Erik Kraft, Trishita Tiwari, Michael Schwarz et al.CCS 2019 · 55 citations
