Randomized Lempel-Ziv Compression for Anti-Compression Side-Channel Attacks

dc.contributor.advisorGuang, Gong
dc.contributor.authorYang, Meng
dc.date.accessioned2018-01-31T15:25:24Z
dc.date.available2018-01-31T15:25:24Z
dc.date.issued2018-01-31
dc.date.submitted2018-01-26
dc.description.abstractSecurity experts confront new attacks on TLS/SSL every year. Ever since the compression side-channel attacks CRIME and BREACH were presented during security conferences in 2012 and 2013, online users connecting to HTTP servers that run TLS version 1.2 are susceptible of being impersonated. We set up three Randomized Lempel-Ziv Models, which are built on Lempel-Ziv77, to confront this attack. Our three models change the deterministic characteristic of the compression algorithm: each compression with the same input gives output of different lengths. We implemented SSL/TLS protocol and the Lempel-Ziv77 compression algorithm, and used them as a base for our simulations of compression side-channel attack. After performing the simulations, all three models successfully prevented the attack. However, we demonstrate that our randomized models can still be broken by a stronger version of compression side-channel attack that we created. But this latter attack has a greater time complexity and is easily detectable. Finally, from the results, we conclude that our models couldn't compress as well as Lempel-Ziv77, but they can be used against compression side-channel attacks.en
dc.identifier.urihttp://hdl.handle.net/10012/12974
dc.language.isoenen
dc.pendingfalse
dc.publisherUniversity of Waterlooen
dc.subjectLempel-Ziv compressionen
dc.subjectencryptionen
dc.subjectcompression side-channel attacken
dc.subjectrandomizationen
dc.subjectTLSen
dc.titleRandomized Lempel-Ziv Compression for Anti-Compression Side-Channel Attacksen
dc.typeMaster Thesisen
uws-etd.degreeMaster of Applied Scienceen
uws-etd.degree.departmentElectrical and Computer Engineeringen
uws-etd.degree.disciplineElectrical and Computer Engineeringen
uws-etd.degree.grantorUniversity of Waterlooen
uws.contributor.advisorGuang, Gong
uws.contributor.affiliation1Faculty of Engineeringen
uws.peerReviewStatusUnrevieweden
uws.published.cityWaterlooen
uws.published.countryCanadaen
uws.published.provinceOntarioen
uws.scholarLevelGraduateen
uws.typeOfResourceTexten

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
yang_meng.pdf
Size:
2.26 MB
Format:
Adobe Portable Document Format
Description:
thesis pdf

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
6.08 KB
Format:
Item-specific license agreed upon to submission
Description: