Главная
Study mode:
on
1
Introduction
2
What are Shared Search Indexes
3
How does a Shared Search Index work
4
SideChannel Attacks
5
How does it work
6
The DF sidechannel
7
The TM sidechannel
8
ScottyP sidechannel attack
9
koshertesting
10
shark mating
11
tag testing
12
results
13
GitHub
14
Scenario
15
Common Areas
16
Summary
17
Questions
Description:
Explore side-channel attacks on shared search indexes in this IEEE Symposium on Security & Privacy conference talk. Delve into the vulnerabilities of multi-tenant full-text search systems like Elasticsearch and Apache Solr. Learn about the STRESS (Search Text RElevance Score Side channel) attack, which exploits TF-IDF scores to leak information about other users' documents. Discover how attackers can map index structures, obtain document placement, and extract sensitive information from co-tenants. Examine real-world demonstrations on popular services such as GitHub and Xen.do. Gain insights into the technical aspects of these attacks, including the DF sidechannel, TM sidechannel, and ScottyP sidechannel. Understand the implications for document retrieval security and explore potential countermeasures to protect against these vulnerabilities in shared search environments.

Side-Channel Attacks on Shared Search Indexes

IEEE
Add to list