loading...
An Independent Evaluation of Web Timing Attack and its Countermeasure
March 04-March 07
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/ARES.2008.1112008 Third International Conference o ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Web timing have attacks become a new threat on the Internet because they enable attackers to reveal users' private information. In this paper, we evaluate the threat of a web timing attack and its countermeasure. Our contribution is to investigate the occurrence conditions of a web timing attack. We also verify the effectiveness of our countermeasure, whose significant feature is fixing the authentication time whereas previous work fixes the response time. For our evaluation, we measure response times of several web applications, and analyze the result with statistical testing. We find that it is difficult to reveal the of username in some types of applications,and we confirm that our countermeasure can thwart web timing attacks.
Index Terms:
Web Timing Attack, Countermeasure, Web Application Security
Citation:
Yoshitaka Nagami, Daisuke Miyamoto, Hiroaki Hazeyama, Youki Kadobayashi, "An Independent Evaluation of Web Timing Attack and its Countermeasure," ares, pp.1319-1324, 2008 Third International Conference on Availability, Reliability and Security, 2008
Usage of this product signifies your acceptance of the Terms of Use.