Websites have a new way to monitor visitors: analyze their SSD performance



Although each file is sandboxed, meaning it is isolated from other websites and from the same device, JavaScript can measure I/O interactions. Then, by running this interaction through previous training convolutional neural networks-a system that uses deep learning to analyze text, audio, and images-the attacker can display the various programs and websites open on the device.

“The attacker continuously tests SSD contention by performing random reads on the main OPFS file,” the researchers explained. “SSD contention caused by user activity causes latency differences in these calculations. By training a convolutional neural network (CNN) on these results, the attacker can use fingerprints on the host’s network by distributing new information using the trained model.

This method has its limitations. First, the OPFS file must be very large—perhaps a gigabyte or more. That requirement means that large-scale attacks can be detected by many users. Additionally, the OPFS file must be stored on the SSD the guest is using. This is usually not a problem for tracking open source websites, since the OPFS file is stored in the browser’s default location. When programs are using SSDs for software, these programs cannot be recognized by FROST.

One of the best ways to avoid FROST attacks is to close tabs as soon as they disappear. Many users can monitor the creation and size of OPFS files provided by unknown websites. The researchers proposed ways to make the browser to block the sidebar. One such way is to limit the maximum file size allowed. There are no indications that FROST has occurred in the wild.

The researchers performed a full Frost attack on the M2 Mac. On Linux, he showed that the old basics (testing SSD latency methods from JavaScript) worked, but it didn’t work.

“However, since the old operating system is the same between macOS and Linux, we expect the functionality to be the same for all versions,” Hannes Weissteiner, one of the co-authors, wrote in an email. “In fact, it is possible to train a model for any situation that produces SSDs reliably.”

The researchers did not test Windows.

The paper linked above provides more technical information. This research is expected to be presented to DIMVA conference in July.



Source link

اترك ردّاً

لن يتم نشر عنوان بريدك الإلكتروني. الحقول الإلزامية مشار إليها بـ *