Skip to Main Content (Press Enter)

Logo UNITO
  • ×
  • Home
  • Pubblicazioni
  • Progetti
  • Persone
  • Competenze
  • Settori
  • Strutture
  • Terza Missione

UNI-FIND
Logo UNITO

|

UNI-FIND

unito.it
  • ×
  • Home
  • Pubblicazioni
  • Progetti
  • Persone
  • Competenze
  • Settori
  • Strutture
  • Terza Missione
  1. Pubblicazioni

Stochastic Models for Remote Timing Attacks

Contributo in Atti di convegno
Data di Pubblicazione:
2025
Abstract:
In this paper, we present the first remote timing attack based on formal stochastic models. Our attack uses queuing models from the field of performance evaluation to estimate the service times of different classes of network requests. By using Bayesian statistics, we then identify opportunities for remote timing attacks by answering the following inverse question: what is the probability that a given network request belongs to a target class, given an estimate of its service time? Our experimental evaluation on popular web applications and websites shows that our investigation is not just a theoretical exercise, because our attack outperforms existing empirical approaches in terms of standard performance figures. We believe that the formal foundations put forward in this paper can be successfully applied to the creation of principled remote timing attacks which are more effective, because better equipped to deal with the complexity of the problem they are trying to solve.
Tipologia CRIS:
04A-Conference paper in volume
Keywords:
web privacy, queuing theory, remote timing attacks
Elenco autori:
Bozzolan, Simone; Olliaro, Diletta; Calzavara, Stefano; Marin, Andrea; Balbo, Gianfranco; Sereno, Matteo
Autori di Ateneo:
SERENO Matteo
Link alla scheda completa:
https://iris.unito.it/handle/2318/2081750
Link al Full Text:
https://iris.unito.it/retrieve/handle/2318/2081750/1901319/popets-2025-0112.pdf
Titolo del libro:
PETS 2025 - The 25th Privacy Enhancing Technologies Symposium
Progetto:
Q-CPS2 - Missione 4 - Componente 2- Investimento 1.3, finanziato dall'Unione europea - NextGenerationEU - Bando SERICS - Codice: PE00000014 - CUP: J33C22002810001
  • Dati Generali
  • Aree Di Ricerca

Dati Generali

URL

https://petsymposium.org/popets/2025/popets-2025-0112.php

Aree Di Ricerca

Settori (4)


PE6_5 - Security, privacy, cryptology, quantum cryptography - (2024)

CIBO, AGRICOLTURA e ALLEVAMENTI - Farmacologia Veterinaria

INFORMATICA, AUTOMAZIONE e INTELLIGENZA ARTIFICIALE - Digitalizzazione della Società e della Pubblica Amministrazione

INFORMATICA, AUTOMAZIONE e INTELLIGENZA ARTIFICIALE - Industria X.0
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 25.6.1.0