login

Remote timing attacks are practical

Computer NetworksPublished 1 March 2005
David Brumley, Dan Boneh
Citations396
SJR quartileQ1
SJR score1.17
SNIP1.37

Abstract

Timing attacks are usually used to attack weak computing devices such as smartcards. We show that timing attacks apply to general software systems. Specifically, we devise a timing attack against OpenSSL. Our experiments show that we can extract private keys from an OpenSSL-based web server running on a machine in the local network. Our results demonstrate that timing attacks against network servers are practical and therefore all security systems should defend against them.

Keywords

Computer Science