Ruhr-Uni-Bochum

Fish and Chips: On the Root Cause of Co-located Website-Fingerprinting Attacks

2026

Conference / Journal

Authors

Zhi Zhang Yinqian Zhang Yuval Yarom Daniel Genkin Chitchanok Chuengsatiansup Xin Zhang Sioli O'Connell Yusi Feng

Research Hub

Hub 2: Secure Hardware Environments

Abstract

Microarchitectural website-fingerprinting attacks use timing information to leak the browsing habits of a victim to co-resident attackers. Microarchitectural leakage in these attacks often comprises multiple sources. While most published attacks claim to identify the cause of leakage, these claims are not always well supported. Thus, so far the question of how to determine what leaks remains mostly unanswered. In this work, we develop a framework for identifying and measuring the contribution of leakage sources to the overall observations the attacker makes. Experimenting with three website-fingerprinting attacks in the literature, we qualitatively identify four main classes of leakage sources: core contention, interrupts, frequency scaling, and cache eviction. We demonstrate cases where we can completely mitigate leakage by controlling these sources. We then show that enabling each of the sources individually leaks enough to allow website-fingerprinting attacks. In the quantitative analysis, we use the correlation between events related to each source and the measured timing in the attacks as a metric to determine the relative contribution of each source to the specific attack. Our work provides insights into the leakage sources of coarse-grained microarchitectural attacks, aiding the design of secure processor systems as well as more effective attacks and defenses.

Tags

Implementation Attacks