USENIX Security2024Top-tier venue
SnailLoad: Exploiting Remote Network Latency Measurements without JavaScript
Stefan Gast, Roland Czerny, Jonas Juffinger, Fabian Rauscher, Simone Franza, Daniel Gruss
Abstract
Inferring user activities on a computer from network traffic is a well-studied attack vector. Previous work has shown that they can infer websites visited, videos watched, and even user actions within specific applications. However, all of these attacks require a scenario where the attacker can observe the (possibly encrypted) network traffic, e.g., through a personin-the-middle (PITM) attack or sitting in physical proximity to monitor WiFi packets. In this paper, we present SnailLoad, a new side-channel attack where the victim loads an asset, e.g., a file or an image, from an attacker-controlled server, exploiting the victim's network latency as a side channel tied to activities on the victim system, e.g., watching videos or websites. SnailLoad requires no JavaScript, no form of code execution on the victim system, and no user interaction but only a constant exchange of network packets, e.g., a network connection in the background. SnailLoad measures the latency to the victim system and infers the network activity on the victim system from the latency variations. We demonstrate SnailLoad in a non-PITM video-fingerprinting attack, where we use a single SnailLoad trace to infer what video a victim user is watching momentarily. For our evaluation, we focused on a set of 10 YouTube videos the victim watches, and show that Snail-Load reaches classification F 1 scores of up to 98 %. We also evaluated SnailLoad in an open-world top 100 website fingerprinting attack, resulting in an F 1 score of 62.8 %. This shows that numerous prior works, based on network traffic observations in PITM attack scenarios, could potentially be lifted to non-PITM remote attack scenarios.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Continuous User Behavior Monitoring using DNS Cache Timing AttacksHannes Weissteiner, Roland Czerny, Simone Franza, Stefan Gast et al.NDSS 2026 · 2 citations
- Time and Time Again: Leveraging TCP Timestamps to Improve Remote Timing AttacksVik Vanderlinden, Tom van Goethem, Mathy VanhoefNDSS 2026
- Lightweight Internet Bandwidth Allocation and Isolation with Fractional Fair SharesMarc Wyss, Yih-Chun Hu, Vincent Lenders, Roland Meier et al.NDSS 2026
Builds on9
- Website Fingerprinting at Internet ScaleAndriy Panchenko, Fabian Lanze, Jan Pennekamp, Thomas Engel et al.NDSS 2016 · 625 citations
- Automated Website Fingerprinting through Deep LearningVera Rimmer, Davy Preuveneers, Marc Juarez, Tom van Goethem et al.NDSS 2018 · 399 citations
- ASLR on the Line: Practical Cache Attacks on the MMUBen Gras, Kaveh Razavi, Erik Bosman, Herbert Bos et al.NDSS 2017 · 276 citations
- Hello from the Other Side: SSH over Robust Cache Covert Channels in the CloudClémentine Maurice, Manuel Weber, Michael Schwarz, Lukas Giner et al.NDSS 2017 · 174 citations
- The Spyware Used in Intimate Partner ViolenceRahul Chatterjee, Periwinkle Doerfler, Hadas Orgad, Sam Havron et al.S&P 2018 · 167 citations
Related papers
- Robust Website Fingerprinting Through the Cache Occupancy ChannelAnatoly Shusterman, Lachlan Kang, Yarden Haskal, Yosef Meltser et al.USENIX Security 2019 · 159 citations
- IdleLeak: Exploiting Idle State Side Effects for Information LeakageFabian Rauscher, Andreas Kogler, Jonas Juffinger, Daniel GrussNDSS 2024
- On Privacy Risks of Watching YouTube over Cellular Networks with Carrier AggregationNitya Lakshmanan, Abdelhak Bentaleb, Byoungjun Choi, Roger Zimmermann et al.UbiComp 2022 · 2 citations
- Defending against Traffic Analysis Attacks with Flexible In-Network ObfuscationGuorui Xie, Qing Li, Zhenning Shi, Gianni Antichi et al.NSDI 2026 · 2 citations
- The Danger of Minimum Exposures: Understanding Cross-App Information Leaks on iOS through Multi-Side-Channel LearningZihao Wang, Jiale Guan, XiaoFeng Wang, Wenhao Wang et al.CCS 2023 · 2 citations
