Algorithmic attacks and timing leaks in distributed systems

dc.contributor.advisorWallach, Dan S.en_US
dc.creatorCrosby, Scott A.en_US
dc.date.accessioned2009-06-04T06:43:39Zen_US
dc.date.available2009-06-04T06:43:39Zen_US
dc.date.issued2005en_US
dc.description.abstractAn important class of remotely applicable security attacks concerns time. You can attack somebody by making their algorithms run in their worst-case behavior rather than common-case behavior. Likewise, the processing time can disclose a secret. If an attacker can observe the time it takes for somebody to process a request, an attacker may learn something about the internal state. The first part of this thesis defines a new class of attacks that perform a remote denial of service by deliberately choosing inputs to make common algorithms slow. These attacks are widespread. We show that vulnerable hash tables are used by Perl and Squid and we illustrate an attack on the Bro IDS. This second part of this thesis analyzes the opportunities for determining a remote party's secret by analyzing processing time remotely over the Internet. Our measurements show that an attacker can potentially time a remote host to 300 nanoseconds over a local area network and less than 20 microseconds over the Internet.en_US
dc.format.extent64 p.en_US
dc.format.mimetypeapplication/pdfen_US
dc.identifier.callnoTHESIS COMP.SCI. 2005 CROSBYen_US
dc.identifier.citationCrosby, Scott A.. "Algorithmic attacks and timing leaks in distributed systems." (2005) Master’s Thesis, Rice University. <a href="https://hdl.handle.net/1911/17765">https://hdl.handle.net/1911/17765</a>.en_US
dc.identifier.urihttps://hdl.handle.net/1911/17765en_US
dc.language.isoengen_US
dc.rightsCopyright is held by the author, unless otherwise indicated. Permission to reuse, publish, or reproduce the work beyond the bounds of fair use or other exemptions to copyright law must be obtained from the copyright holder.en_US
dc.subjectComputer scienceen_US
dc.titleAlgorithmic attacks and timing leaks in distributed systemsen_US
dc.typeThesisen_US
dc.type.materialTexten_US
thesis.degree.departmentComputer Scienceen_US
thesis.degree.disciplineEngineeringen_US
thesis.degree.grantorRice Universityen_US
thesis.degree.levelMastersen_US
thesis.degree.nameMaster of Scienceen_US
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
1425813.PDF
Size:
18.12 MB
Format:
Adobe Portable Document Format