activity
20152021
most citedThe Spy in the Sandbox -- Practical Cache Attacks in Javascript

44 citations · 50 across the 3 of their papers we have counts for

collaborators

6 papers

cs.CR20214 cited

Prime+Probe 1, JavaScript 0: Overcoming Browser-based Side-Channel Defenses

Anatoly Shusterman, Ayush Agarwal, Sioli O'Connell +3

The "eternal war in cache" has reached browsers, with multiple cache-based side-channel attacks and countermeasures being suggested. A common approach for countermeasures is to dis…

cs.CR2019

Cross-Router Covert Channels

Adar Ovadya, Rom Ogen, Yakov Mallah +2

Many organizations protect secure networked devices from non-secure networked devices by assigning each class of devices to a different logical network. These two logical networks,…

cs.CR20192 cited

Sensor Defense In-Software (SDI):Practical Software Based Detection of Spoofing Attacks on Position Sensor

Kevin Sam Tharayil, Benyamin Farshteindiker, Shaked Eyal +6

Position sensors, such as the gyroscope, the magnetometer and the accelerometer, are found in a staggering variety of devices, from smartphones and UAVs to autonomous robots. Sever…

cs.CR2018

Robust Website Fingerprinting Through the Cache Occupancy Channel

Anatoly Shusterman, Lachlan Kang, Yarden Haskal +4

Website fingerprinting attacks, which use statistical analysis on network traffic to compromise user privacy, have been shown to be effective even if the traffic is sent over anony…

cs.CR2018

Shattered Trust: When Replacement Smartphone Components Attack

Omer Shwartz, Amir Cohen, Asaf Shabtai +1

Phone touchscreens, and other similar hardware components such as orientation sensors, wireless charging controllers, and NFC readers, are often produced by third-party manufacture…

cs.CR201544 cited

The Spy in the Sandbox -- Practical Cache Attacks in Javascript

Yossef Oren, Vasileios P. Kemerlis, Simha Sethumadhavan +1

We present the first micro-architectural side-channel attack which runs entirely in the browser. In contrast to other works in this genre, this attack does not require the attacker…