Back to results

Università degli studi di Trento

Security Implications of Web Caching

Abstract

dc:description

The World Wide Web relies heavily on caching to improve performance and scalability, yet the security aspects of this mechanism remain poorly understood. This thesis investigates the security posture of web caches following three incremental steps: web cache detection, exploitation, and uncovering of novel attack primitives. First, we introduce methodologies to detect web caches using response headers, timing analysis, and subtle header variations, comparing their effectiveness and limitations. Building on this foundation, we present large-scale techniques for detecting vulnerabilities such as Web Cache Deception (WCD) and cache poisoning. We focus on understudied vulnerabilities for which no automated detection tools exist. Our empirical analysis includes the largest WCD study to date, identifying 1,188 vulnerable domains and challenging prior assumptions about its real-world severity. We then explore the broader security implications of cache misuse, showing how WCD can be chained with other web vulnerabilities to create complex attack vectors enabling data leakage and supply chain compromise, and how caching of security tokens can severely impact the security of web users. Finally, we introduce Web Cache Overflow (WCO), a new attack primitive that exploits imprecise cache keying to degrade cache performance and cause Denial of Service. Overall, this work provides a comprehensive exploration of web cache vulnerabilities, from foundational detection challenges to large-scale exploitation and mitigation, and serves as a basis for further research in this critical area. Through these contributions, we advance the state of the art in web cache security through systematic detection methodologies, large-scale vulnerability analysis, and the discovery of new attack vectors, accompanied by open-source tools to foster further research and defensive development. Our findings underscore the need for improved security practices in web caching and provide actionable insights for both researchers and practitioners.

Degree

thesis:*
Grantor dc:publisher
Università degli studi di Trento
Year dc:date
2026

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Golinelli, Matteo
Contributors dc:contributor
  • Crispo, Bruno

Subjects

dc:subject × 1

Rights

dc:rights
Statement dc:rights
  • info:eu-repo/semantics/openAccess
  • license:Creative commons
  • license uri:http://creativecommons.org/licenses/by-sa/4.0/
Language dc:language
eng

Identifiers

dc:identifier.*
OAI identifier oai:identifier
oai:iris.unitn.it:11572/478270

Chain of custody

source
Harvested from
Università degli Studi di Trento
Base URL
iris.unitn.it/oai/request
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Golinelli, Matteo. Security Implications of Web Caching. Università degli studi di Trento, 2026. https://hdl.handle.net/11572/478270