Web Timing Attacks Made Practical
by Timothy Morgan & Jason Morgan Timing side-channel attacks are a well-known class of flaw in cryptographic systems and applications in general. While these issues have been researched for decades, the complexities involved in obtaining accurate timing measurements and performing accurate statistical analysis has prevented the average pentester from identifying and exploiting these issues on a day-to-day basis. In this paper, we build on past research to make remote timing attacks practical against modern web applications. We scrutinize both methods of data collection and statistical analysis used by previous researchers, significantly improving results in both areas. We implement an adaptive Kalman filter, which provides greater accuracy in classifying timing differences, making timing attacks more practical in congested networks and speeding up attacks in ideal conditions. As part of this research, a new open source timing attack tool suite is being released to the community.

DEF CON 32 - Listen to the Whispers: Web Timing Attacks that Actually Work - James Kettle

Breaking Access Controls With BLEKey

16. Side-Channel Attacks

Listen to the Whispers: Web Timing Attacks that Actually Work

Attacking AI - Jason Haddix - NDC Security 2026

HEIST: HTTP Encrypted Information can be Stolen Through TCP-Windows

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026

LayerOne 2026 - Trusted Senders and Untrusted Outcomes (Priyank Nigam)

6. Monte Carlo Simulation

Web Application Firewalls: Analysis of Detection Logic

Spectre and Meltdown attacks explained understandably

Cache Side Channel Attack: Exploitability and Countermeasures

HTTP Cookie Hijacking in the Wild: Security and Privacy Implications

Inside Anthropic, the $965 Billion AI Juggernaut | The Circuit

Exploiting Network Printers

Last-Level Cache Side-Channel Attacks are Practical

Casey Muratori – The Big OOPs: Anatomy of a Thirty-five-year Mistake – BSC 2025

But what is quantum computing? (Grover's Algorithm)

Cracking the Lens: Targeting HTTP's Hidden Attack-Surface

