Compression side channel attacks target systems that compress data before encrypting it. By taking advantage of the fact that compression causes message lengths to be connected to message contents, they enable attackers to exfiltrate encrypted data without access to the secret keys. This paper introduces new techniques for compression side channel attacks on databases. We show how compression side channels can be used to attack not only data that is currently stored in an encrypted table, but also deleted data that was formerly stored in that table. We also demonstrate how a number of algorithmic techniques not previously used in this space can dramatically speed up detection and extraction of secret data from widely used database storage engines. We then demonstrate that our attacks outperform the recent DBREACH compression side channel attacks (IEEE S&P 2023) in both functionality and performance. Specifically, we introduce a family of G-DBREACH attack techniques, each of which improves on one facet of prior work, and all of which can be used together in concert. First, the Ghost-DBREACH attack uses the template of DBREACH attacks, but also compromises deleted data from datatabases. Next, the Group-DBREACH attack uses group testing to accelerate string detection attacks. Finally, the Gallop-DBREACH attack shows how to replace various linear-cost operations in the previous attacks with logarithmic-cost ones, providing even more aggressive speedups of up to \(9{\times }.\)

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

G-DBREACH Attacks: Algorithmic Techniques for Faster and Stronger Compression Side Channels

  • Britney Bourassa,
  • Yan Michalevsky,
  • Saba Eskandarian

摘要

Compression side channel attacks target systems that compress data before encrypting it. By taking advantage of the fact that compression causes message lengths to be connected to message contents, they enable attackers to exfiltrate encrypted data without access to the secret keys. This paper introduces new techniques for compression side channel attacks on databases. We show how compression side channels can be used to attack not only data that is currently stored in an encrypted table, but also deleted data that was formerly stored in that table. We also demonstrate how a number of algorithmic techniques not previously used in this space can dramatically speed up detection and extraction of secret data from widely used database storage engines. We then demonstrate that our attacks outperform the recent DBREACH compression side channel attacks (IEEE S&P 2023) in both functionality and performance. Specifically, we introduce a family of G-DBREACH attack techniques, each of which improves on one facet of prior work, and all of which can be used together in concert. First, the Ghost-DBREACH attack uses the template of DBREACH attacks, but also compromises deleted data from datatabases. Next, the Group-DBREACH attack uses group testing to accelerate string detection attacks. Finally, the Gallop-DBREACH attack shows how to replace various linear-cost operations in the previous attacks with logarithmic-cost ones, providing even more aggressive speedups of up to \(9{\times }.\)