Opportunities and Limits of Remote Timing Attacks

dc.contributor.authorCrosby, Scott A.en_US
dc.contributor.authorRiedi, Rudolf H.en_US
dc.contributor.authorWallach, Dan S.en_US
dc.date.accessioned2017-08-02T22:03:04Zen_US
dc.date.available2017-08-02T22:03:04Zen_US
dc.date.issued2007-05-26en_US
dc.date.noteMay 26, 2007en_US
dc.description.abstractMany algorithms can take a variable amount of time to complete depending on the data being processed. These timing differences can sometimes disclose confidential information. Indeed, researchers have been able to reconstruct an RSA private key purely by querying an SSL web server and timing the results. Our work analyzes the limits of attacks based on accurately measuring network response times and jitter over a local network and across the Internet. We present the design of filters to significantly reduce the effects of jitter, allowing an attacker to measure events with 15-100μs accuracy across the Internet, and as good as 100ns over a local network. Notably, security-related algorithms on web servers and other network servers need to be carefully engineered to avoid timing channel leaks at the accuracy demonstrated in this paper.en_US
dc.format.extent36 ppen_US
dc.identifier.citationCrosby, Scott A., Riedi, Rudolf H. and Wallach, Dan S.. "Opportunities and Limits of Remote Timing Attacks." (2007) https://hdl.handle.net/1911/96356.en_US
dc.identifier.digitalTR07-03en_US
dc.identifier.urihttps://hdl.handle.net/1911/96356en_US
dc.language.isoengen_US
dc.rightsYou are granted permission for the noncommercial reproduction, distribution, display, and performance of this technical report in any format, but this permission is only for a period of forty-five (45) days from the most recent time that you verified that this technical report is still available from the Computer Science Department of Rice University under terms that include this permission. All other rights are reserved by the author(s).en_US
dc.titleOpportunities and Limits of Remote Timing Attacksen_US
dc.typeTechnical reporten_US
dc.type.dcmiTexten_US
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
TR07-03.pdf
Size:
347.05 KB
Format:
Adobe Portable Document Format