Zur Hauptnavigation wechseln Zur Suche wechseln Zum Hauptinhalt wechseln

PerfWeb: How to Violate Web Privacy with Hardware Performance Events

Berk Gülmezoglu, Thomas Eisenbarth, Berk Sunar, Andreas Zankl

Abstract

The browser history reveals highly sensitive information about users, such as financial status, health conditions, or political views. Private browsing modes and anonymity networks are consequently important tools to preserve the privacy not only of regular users but in particular of whistleblowers and dissidents. Yet, in this work we show how a malicious application can infer opened websites from Google Chrome in Incognito mode and from Tor Browser by exploiting hardware performance events (HPEs). In particular, we analyze the browsers’ microarchitectural footprint with the help of advanced Machine Learning techniques: k-th Nearest Neighbors, Decision Trees, Support Vector Machines, and in contrast to previous literature also Convolutional Neural Networks. We profile 40 different websites, 30 of the top Alexa sites and 10 whistleblowing portals, on two machines featuring an Intel and an ARM processor. By monitoring retired instructions, cache accesses, and bus cycles for at most 5 s we manage to classify the selected websites with a success rate of up to 86.3%. The results show that hardware performance events can clearly undermine the privacy of web users. We therefore propose mitigation strategies that impede our attacks and still allow legitimate use of HPEs.
OriginalspracheEnglisch
TitelComputer Security – ESORICS 2017
Redakteure/-innenSimon N. Foley, Dieter Gollmann, Einar Snekkenes
Seitenumfang18
Band10493
Herausgeber (Verlag)Springer Verlag
Erscheinungsdatum12.08.2017
Seiten80-97
ISBN (Print)978-3-319-66398-2
ISBN (elektronisch)978-3-319-66399-9
DOIs
PublikationsstatusVeröffentlicht - 12.08.2017
Veranstaltung22nd European Symposium on Research in Computer Security - Oslo, Norwegen
Dauer: 11.09.201715.09.2017

UN SDGs

Dieser Output leistet einen Beitrag zu folgendem(n) Ziel(en) für nachhaltige Entwicklung

  1. SDG 9 – Industrie, Innovation und Infrastruktur
    SDG 9 – Industrie, Innovation und Infrastruktur
  2. SDG 11 – Nachhaltige Städte und Gemeinschaften
    SDG 11 – Nachhaltige Städte und Gemeinschaften
  3. SDG 12 – Verantwortungsvoller Konsum und Produktion
    SDG 12 – Verantwortungsvoller Konsum und Produktion

Fingerprint

Untersuchen Sie die Forschungsthemen von „PerfWeb: How to Violate Web Privacy with Hardware Performance Events“. Zusammen bilden sie einen einzigartigen Fingerprint.

Zitieren