Determining visited websites through the analysis of SSD activity from the web browser

A group of researchers from Graz University of Technology (Austria) developed a side-channel attack technique called FROST (Fingerprinting Remotely using OPFS-based SSD Timing), which allows determining the websites users are visiting with an accuracy of 88.95% and the applications running on the system with an accuracy of 95.83% through analyzing the activity of the SSD drive from JavaScript code executed in the browser. This method can also be used to establish a hidden communication channel between a locally running application and the JavaScript code executed in the browser. The data exchange performance in Linux was 661 bit/s, while in macOS it was 892 bit/s.

The attack is based on the specific nature of how access times to the SSD drive change during the opening of a website or the launching of a web application, which is unique to that site or application. By using typical access time signatures for pre-measured websites and applications, one can distinguish their characteristic activity against a backdrop of other input/output operations. In the context of the executed attack, delays in input/output operations are matched with the signatures of websites and applications.
A convolutional neural network was employed to identify patterns against the noise from external input/output.

For the method to work in the browser, the OPFS (Origin-Private FileSystem) API is utilized, which allows creating files in the local file system (files are created in an isolated part of the file system associated with the site). Access time to the SSD drive is analyzed by measuring delays in identical data operations. To bypass the influence of the page cache on file operations during the attack, it is necessary to create files of very large sizes that exceed the size of available RAM.

As a countermeasure against the attack, browser manufacturers are advised to require separate user confirmation for accessing the OPFS API or to limit the maximum file size to a value not exceeding the size of the RAM. Currently, Chrome and Safari allow creating files through the OPFS API that occupy up to 60% of the available disk space.

Chromium developers at Google do not recognize such side-channel attacks as vulnerabilities. Safari developers at Apple do not rule out the future implementation of methods to counter these attacks. Mozilla has acknowledged the issue but has not yet implemented a fix.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster