Proceedings 2021 Network and Distributed System Security Symposium 2021
DOI: 10.14722/ndss.2021.23104
|View full text |Cite
|
Sign up to set email alerts
|

Awakening the Web's Sleeper Agents: Misusing Service Workers for Privacy Leakage

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
6
0

Year Published

2021
2021
2022
2022

Publication Types

Select...
6
3

Relationship

0
9

Authors

Journals

citations
Cited by 18 publications
(6 citation statements)
references
References 28 publications
(22 reference statements)
0
6
0
Order By: Relevance
“…Similarly, in older browser versions, the attacker could simply read out the computed style to infer whether a certain URL was previously visited [3,43]. More recently, Karami et al [14] and Lee et al [22] showed that the service worker cache could also be exploited to infer whether a user previously visited a specific website.…”
Section: Related Workmentioning
confidence: 99%
“…Similarly, in older browser versions, the attacker could simply read out the computed style to infer whether a certain URL was previously visited [3,43]. More recently, Karami et al [14] and Lee et al [22] showed that the service worker cache could also be exploited to infer whether a user previously visited a specific website.…”
Section: Related Workmentioning
confidence: 99%
“…They run in the background of a web page and can intercept, modify, and cache resources to create offline web application. Karami et al [32] introduced leak techniques to detect if a service worker is registered for a specific origin. They used iframes as an inclusion method on resources that have previously been cached by a service worker.…”
Section: A2 Detectable Difference: Api Usagementioning
confidence: 99%
“…Specifically, the authors investigated the potential security vulnerabilities of Service Workers and they demonstrated multiple attack scenarios from cryptojacking to malicious computations (e.g., distributed password cracking), as well as Distributed Denial of Service attacks. Karami et al in [4] studied attacks that aim to exploit Service Workers vulnerabilities to ex-filtrate important privacy information from the user. Specifically, they demonstrated two history-sniffing attacks that exploit the lack of appropriate isolation in these browsers including a non-destructive cache-based version.…”
Section: Related Workmentioning
confidence: 99%
“…In [3], authors present a framework that exploits Service Workers functionality to launch attacks like DDoS, cryptojacking and distributed password cracking. In [4], authors investigate the potential privacy leaks that malicious Service Workers can cause on a victim's browser.…”
Section: Introductionmentioning
confidence: 99%