Projects per year
Abstract
Prior work showed that variations in SSD access time can be used to leak information about user activity, e.g., the websites a user accesses, and for covert data transmission. To achieve this, SSD contention side channels require accurate high-resolution timing measurements of I/O operations, e.g., through the io_uring kernel API. However, the impact of these attacks is limited in their requirement for native code execution on the victim’s system.
In this paper, we show that SSD contention side channels can be mounted by a remote attacker from within the browser, without native code execution. Our attack FROST targets the Origin Private File System (OPFS) API in JavaScript, allowing us to create and access files on the disk, within the browser’s sandboxed environment. While a challenge in prior work was to evict the OS page cache, we devise an approach that instead bypasses the page cache, enabling fast SSD contention measurements from JavaScript without any user interaction. To evaluate the effectiveness of FROST on macOS and Linux, we build a covert channel that exfiltrates data from a native application to the malicious website with a true channel capacity of 661.63 bit/s on a Linux machine, and 891.77 bit/s on a macOS machine. To evaluate the FROST in a side-channel scenario, we mount a website- and an application-fingerprinting attack on users of macOS systems. We can predict accessed websites with an F1 score of 88.95 %, and accessed application with an F1 score of 95.83 %, demonstrating the privacy implications our attack has on regular users.
In this paper, we show that SSD contention side channels can be mounted by a remote attacker from within the browser, without native code execution. Our attack FROST targets the Origin Private File System (OPFS) API in JavaScript, allowing us to create and access files on the disk, within the browser’s sandboxed environment. While a challenge in prior work was to evict the OS page cache, we devise an approach that instead bypasses the page cache, enabling fast SSD contention measurements from JavaScript without any user interaction. To evaluate the effectiveness of FROST on macOS and Linux, we build a covert channel that exfiltrates data from a native application to the malicious website with a true channel capacity of 661.63 bit/s on a Linux machine, and 891.77 bit/s on a macOS machine. To evaluate the FROST in a side-channel scenario, we mount a website- and an application-fingerprinting attack on users of macOS systems. We can predict accessed websites with an F1 score of 88.95 %, and accessed application with an F1 score of 95.83 %, demonstrating the privacy implications our attack has on regular users.
| Original language | English |
|---|---|
| Title of host publication | Detection of Intrusions and Malware, and Vulnerability Assessment - 23rd International Conference, DIMVA 2026, Proceedings |
| Publisher | Springer, Cham |
| Publication status | Accepted/In press - 4 Apr 2026 |
| Event | 23rd Conference on Detection of Intrusions and Malware & Vulnerability Assessment, DIMVA 2026 - Chania, Greece Duration: 1 Jul 2026 → 3 Jul 2026 |
Conference
| Conference | 23rd Conference on Detection of Intrusions and Malware & Vulnerability Assessment, DIMVA 2026 |
|---|---|
| Country/Territory | Greece |
| City | Chania |
| Period | 1/07/26 → 3/07/26 |
Fields of Expertise
- Information, Communication & Computing
Fingerprint
Dive into the research topics of 'FROST: Fingerprinting Remotely using OPFS-based SSD Timing'. Together they form a unique fingerprint.-
EU - FSSec - Foundations for Sustainable Security
Gruss, D. (Project manager on research unit)
1/03/23 → 29/02/28
Project: Research project
-
Special Research Area (SFB) F85 Semantic and Cryptographic Foundations of Security and Privacy by Compositional Design
Mangard, S. (Project manager on research unit)
1/01/23 → 31/12/26
Project: Research project
-
FWF - NeRAM - Next-Generation Rowhammer Attacks and Mitigations
Gruss, D. (Project manager on research unit)
1/12/22 → 30/11/25
Project: Research project
Activities
- 1 Talk at conference or symposium
-
FROST: Fingerprinting Remotely using OPFS-based SSD Timing
Weissteiner, H. (Speaker)
2 Jul 2026Activity: Talk or presentation › Talk at conference or symposium › Science to science
Cite this
- APA
- Standard
- Harvard
- Vancouver
- Author
- BIBTEX
- RIS