USENIX Security2025Top-tier venue
Mitigating Injection Attacks against E2EE Applications via View-Based Partitioning
Andrés Fábrega, Samuel Breckenridge, Armin Namavari, Thomas Ristenpart
Abstract
A recent line of work has explored injection attacks against end-to-end encrypted (E2EE) applications. These involve sending adversarial content to a target victim E2EE client, thereby "injecting it" into otherwise honest client state, followed by monitoring some encrypted backup or other server-side state to violate confidentiality. These attacks exploit features such as compression before encryption of backups, and practitioners so far lack a way to prevent these attacks while retaining practicality. We address this gap by introducing a framework for preventing injection attacks. Underlying the framework is a new approach that we call view-based partitioning, which allows application features to be designed to ensure that injection attacks cannot be exploited to leak confidential information. At the same time, our framework allows for efficiency: intuitively, application state can be partitioned according to potential adversarial views, and within individual views (e.g., all the messages visible to a particular sender in an E2EE messaging app) compression and other performance features can be used without risk of injection attacks. We provide, for the first time, a formal security model for injection attacks, and prove that designers can use our framework to ensure injection attacks fail. Finally, we evaluate various implementations of our framework as applied to backing up E2EE application state via SQLite and XML databases, showing that we can achieve injection resistance with negligible performance overheads.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on17
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Dedup Est Machina: Memory Deduplication as an Advanced Exploitation VectorErik Bosman, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaS&P 2016 · 252 citations
- Dancing on the Lip of the Volcano: Chosen Ciphertext Attacks on Apple iMessageChristina Garman, Matthew Green, Gabriel Kaptchuk, Ian Miers et al.USENIX Security 2016 · 62 citations
- Qapla: Policy compliance for database-backed systemsAastha Mehta, Eslam Elnikety, Katura Harvey, Deepak Garg et al.USENIX Security 2017 · 46 citations
- Zeph: Cryptographic Enforcement of End-to-End Data PrivacyLukas Burkhalter, Nicolas Küchler, Alexander Viand, Hossein Shafagh et al.OSDI 2021 · 35 citations
Related papers
- Injection Attacks Against End-to-End Encrypted ApplicationsAndrés Fábrega, Carolina Ortega Pérez, Armin Namavari, Ben Nassi et al.S&P 2024 · 9 citations
- Exploiting Leakage in Password Managers via Injection AttacksAndrés Fábrega, Armin Namavari, Rachit Agarwal, Ben Nassi et al.USENIX Security 2024 · 1 citation
- Security Analysis of the WhatsApp End-to-End Encrypted Backup ProtocolGareth T. Davies, Sebastian H. Faller, Kai Gellert, Tobias Handirk et al.CRYPTO 2023 · 29 citations
- Wink: Deniable Secure MessagingAnrin Chakraborti, Darius Suciu, Radu SionUSENIX Security 2023
- Adversarial Detection Avoidance Attacks: Evaluating the robustness of perceptual hashing-based client-side scanningShubham Jain, Ana-Maria Cretu, Yves-Alexandre de MontjoyeUSENIX Security 2022
