TY - JOUR
T1 - Empirical Analysis of Remote Keystroke Inference Attacks and Defenses on Incremental Search
AU - Chen, Zhiyu
AU - Mao, Jian
AU - Lin, Qixiao
AU - Ma, Liran
AU - Liu, Jianwei
N1 - Publisher Copyright:
© The author(s) 2025.
PY - 2025
Y1 - 2025
N2 - Incremental search provides real-time suggestions as users type their queries. However, recent studies demonstrate that its encrypted search traffic can disclose privacy-sensitive data through side channels. Specifically, attackers can derive information about user keystrokes from observable traffic features, like packet sizes, timings, and directions, thereby inferring the victim's entered search query. This vulnerability is known as a remote keystroke inference attack. While various attacks leveraging different traffic features have been developed, accompanied by obfuscation-based countermeasures, there is still a lack of overall and in-depth understanding regarding these attacks and defenses. To fill this gap, we conduct the first comprehensive evaluation of existing remote keystroke inference attacks and defenses. We carry out extensive experiments on five well-known incremental search websites, all listed in Alexa's top 50, to evaluate and compare their real-world performance. The results demonstrate that attacks utilizing multidimensional request features pose the greatest risk to user privacy, and random padding is currently considered the optimal defense balancing both efficacy and resource demands. Our work sheds light on the real-world implications of remote keystroke inference attacks and provides developers with guidelines to enhance privacy protection strategies.
AB - Incremental search provides real-time suggestions as users type their queries. However, recent studies demonstrate that its encrypted search traffic can disclose privacy-sensitive data through side channels. Specifically, attackers can derive information about user keystrokes from observable traffic features, like packet sizes, timings, and directions, thereby inferring the victim's entered search query. This vulnerability is known as a remote keystroke inference attack. While various attacks leveraging different traffic features have been developed, accompanied by obfuscation-based countermeasures, there is still a lack of overall and in-depth understanding regarding these attacks and defenses. To fill this gap, we conduct the first comprehensive evaluation of existing remote keystroke inference attacks and defenses. We carry out extensive experiments on five well-known incremental search websites, all listed in Alexa's top 50, to evaluate and compare their real-world performance. The results demonstrate that attacks utilizing multidimensional request features pose the greatest risk to user privacy, and random padding is currently considered the optimal defense balancing both efficacy and resource demands. Our work sheds light on the real-world implications of remote keystroke inference attacks and provides developers with guidelines to enhance privacy protection strategies.
KW - Web application
KW - incremental search
KW - side-channel attack
KW - traffic analysis
KW - user privacy
UR - https://www.scopus.com/pages/publications/105013551458
U2 - 10.26599/TST.2024.9010100
DO - 10.26599/TST.2024.9010100
M3 - 文章
AN - SCOPUS:105013551458
SN - 1007-0214
VL - 30
SP - 2434
EP - 2451
JO - Tsinghua Science and Technology
JF - Tsinghua Science and Technology
IS - 6
ER -