Continuous User Behavior Monitoring using DNS Cache Timing Attacks
Hannes Weissteiner, Roland Czerny, Simone Franza, Stefan Gast, Johanna Ullrich, Daniel Gruss
摘要
—The Domain Name System (DNS) is a core component of the Internet. Clients query DNS servers to translate domain names to IP addresses. Local DNS caches alleviate the time it takes to query a DNS server, thereby reducing delays to connection attempts. Prior work showed that DNS caches can be exploited via timing attacks to test whether a user has visited a specific website recently but lacked eviction capabilities, i.e. , could not monitor when precisely a user accessed a website, others focused on DNS caches in routers. All prior attacks required some form of code execution (e.g., native code, Java, or JavaScript) on the victim’s system, which is also not always possible. We introduce DMT, a novel Evict+Reload attack to continuously monitor a victim’s Internet accesses through the local, system-wide DNS cache. The foundation of DMT is reliable DNS cache eviction: We present 4 DNS cache eviction techniques to evict the local DNS cache in unprivileged and sandboxed native attacks, virtualized cross-VM attacks, as well as browser-based attacks, i.e. , a website with JavaScript and a scriptless attack exploiting the serial loading of fonts integrated in websites. Our attack works both in default settings and when using DNS-over-TLS, DNSSEC, or non-default DNS forwarders for security. We observe eviction times of 77 . 267 ms on average across all contexts, using our fastest eviction primitive and reload and measurement times of 685 . 86 ms on average in the best case (cross-VM attack) for 100 domains and 14 . 710 s on average in the worst case (JavaScript-based attack). Hence, the blind spot of our attack for a granularity of five minutes is smaller than 0 . 26 % in the best case, and 4 . 92 % in the worst case, resulting in a reliable attack. In an end-to-end cross-VM attack, we can detect website visits from a list of 103 websites (in an open-world scenario) reliably with an F 1 score of 92 . 48 % within less than one second. In our JavaScript-based attack, we achieve F 1 scores of 82 . 86 % and 78 . 89 % for detecting accesses to 10 websites, with and without DNSSEC, respectively. We argue that DMT leaks information valuable for extortion and scam campaigns, or to serve exploits tailored to the victim’s EDR solution.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper19
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 被引用 632 次
- Website Fingerprinting at Internet ScaleAndriy Panchenko, Fabian Lanze, Jan Pennekamp, Thomas Engel 等NDSS 2016 · 被引用 625 次
- k-fingerprinting: A Robust Scalable Website Fingerprinting TechniqueJamie Hayes, George DanezisUSENIX Security 2016 · 被引用 474 次
- Automated Website Fingerprinting through Deep LearningVera Rimmer, Davy Preuveneers, Marc Juarez, Tom van Goethem 等NDSS 2018 · 被引用 399 次
- Triplet Fingerprinting: More Practical and Portable Website Fingerprinting with N-shot LearningPayap Sirinam, Nate Mathews, Mohammad Saidur Rahman, Matthew WrightCCS 2019 · 被引用 268 次
相关 Paper
- Timeless Timing Attacks and Preload Defenses in Tor's DNS CacheRasmus Dahlberg, Tobias PullsUSENIX Security 2023
- A Systematic Evaluation of Novel and Existing Cache Side ChannelsFabian Rauscher, Carina Fiedler, Andreas Kogler, Daniel GrussNDSS 2025
- DNS FLaRE: A Flush-Reload Attack on DNS ForwardersGilad Moav, Yehuda Afek, Anat Bremler-Barr, Amit KleinUSENIX Security 2025
- Eviction Notice: Reviving and Advancing Page Cache AttacksSudheendra Raghav Neela, Jonas Juffinger, Lukas Maar, Daniel GrussNDSS 2026 · 被引用 2 次
- Good Cache, BAD Cache: Exploiting DNSSEC Validation Failures for DNS Cache Poisoning AttacksShiming Liu, Yunyi Zhang, Chaoyi Lu, Baojun Liu 等CCS 2026
