Attacking Suggest Boxes in Web Applications Over HTTPS Using Side-Channel

Alexander Schaub, Emmanuel Schneider, Alexandros Hollender, Vinicius Calasans, Laurent Jolie, Robin Touillon, Annelie Heuser, Sylvain Guilley, Olivier Rioul · 2014

Web applications are subject to several types of attacks. In particular, side-channel attacks consist in performing a statistical anal- ysis of the web trac to gain sensitive information about a client. In this paper, we investigate how side-channel leaks can be used on search engines such as Google or Bing to retrieve the client's search query. In contrast to previous works, due to payload randomization and compres- sion, it is not always possible to uniquely map a search query to a web trac signature and hence stochastic algorithms must be used. They yield, for the French language, an exact recovery of search word in more than 30% of the cases. Finally, we present some methods to mitigate such side-channel leaks.

Read the paper · More papers on PaperTik