Preliminary research
Time for ACKrobatics: Abusing TCP Timestamps to Improve Remote Timing Attacks
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
Uses the server's own TCP timestamp in its ACK as the clock for a remote timing attack, so client-side jitter drops out; coalescing many pipelined requests into one segment multiplies the measured runtime. Resolution goes from 25 microseconds to 5, and to 750 ns where microsecond timestamps are on, cutting 10k requests to 200, and the attack distributes across hosts. A scan of 880k servers finds 88% with timestamps enabled; demos hit Lucky 13 and OpenSSH.
Record
- Researcher
- Vik Vanderlinden, Tom Van Goethem and Mathy Vanhoef
- Format
- Whitepaper
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Vik Vanderlinden, Tom Van Goethem and Mathy Vanhoef, first published at the original source. Preserved copies are kept so the citation survives its host.