Proceedings 2020 Network and Distributed System Security Symposium 2020
DOI: 10.14722/ndss.2020.24278
|View full text |Cite
|
Sign up to set email alerts
|

Cross-Origin State Inference (COSI) Attacks: Leaking Web Site States through XS-Leaks

Abstract: In a Cross-Origin State Inference (COSI) attack, an attacker convinces a victim into visiting an attack web page, which leverages the cross-origin interaction features of the victim's web browser to infer the victim's state at a target web site. COSI attacks can have serious consequences including determining if the victim has an account or is the administrator of a prohibited target site, determining if the victim owns sensitive content or is the owner of a specific account at the target site.While COSI attac… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
9
0

Year Published

2021
2021
2023
2023

Publication Types

Select...
5
1

Relationship

0
6

Authors

Journals

citations
Cited by 12 publications
(9 citation statements)
references
References 16 publications
(23 reference statements)
0
9
0
Order By: Relevance
“…One of this paper's main contributions is to evaluate the impact of XS-Leak attacks on different web browsers 𝑤 ∈ 𝑊 . We systematically extend the work of Sudhodanan et al [51] by including a broad set of relevant browsers, both desktop and mobile, and extending the set of XS-Leak attacks significantly.…”
Section: Xsinator: Automatic Browser Evaluationmentioning
confidence: 99%
See 4 more Smart Citations
“…One of this paper's main contributions is to evaluate the impact of XS-Leak attacks on different web browsers 𝑤 ∈ 𝑊 . We systematically extend the work of Sudhodanan et al [51] by including a broad set of relevant browsers, both desktop and mobile, and extending the set of XS-Leak attacks significantly.…”
Section: Xsinator: Automatic Browser Evaluationmentioning
confidence: 99%
“…ContentDocument XFO Sudhodanan et al [51] In GC, when a page is not allowed to be embedded on a cross-origin page because of X-Frame-Options, an error page is shown.…”
Section: Html Elementsmentioning
confidence: 99%
See 3 more Smart Citations