Stealthy traffic analysis of low-latency anonymous communication using throughput fingerprinting

Stealthy traffic analysis of low-latency anonymous communication using throughput fingerprinting
复制标题

DOI:
10.1145/2046707.2046732
复制
发表时间:
2011-09
期刊:
--
影响因子:
--
通讯作者:
Prateek Mittal;Ahmed Khurshid;Joshua Juen;M. Caesar;N. Borisov
Prateek Mittal;Ahmed Khurshid;Joshua Juen;M. Caesar;N. Borisov
中科院分区:
其他
文献类型:
--
作者:
Prateek Mittal;Ahmed Khurshid;Joshua Juen;M. Caesar;N. Borisov

文献摘要

被引文献

相似文献

Tor 等匿名系统旨在使用户能够以控制少量机器的对手无法追踪的方式进行通信。为了向用户提供高效的服务,这些匿名系统在中间中继之间发送流量时充分利用转发能力。在本文中,我们表明这样做会泄露有关电路(路径)中 Tor 中继集的信息。我们提出的攻击具有高置信度并且仅基于吞吐量信息,可以(a)减少攻击者对任何可观察吞吐量的 Tor 电路的瓶颈中继的不确定性,(b)当可以通过多个连接观察电路吞吐量时准确识别 Tor 用户的保护中继,以及(c)识别两个并发 TCP 连接是否属于同一 Tor 用户,从而打破不可链接性。我们的攻击是隐秘的,用户或 Tor 中继无法轻易检测到。我们通过实时 Tor 网络进行实验来验证我们的攻击。我们发现,攻击者可以大幅减少可观察到吞吐量的 Tor 电路的瓶颈中继分布的熵——在中值情况下,熵减少了 2 倍。来自单个 Tor 电路的此类信息泄漏可以通过多个连接进行组合,以准确识别用户的保护继电器。最后,我们还能够在 5 分钟内链接来自同一启动器的两个连接,交叉错误率低于 1.5%。与之前对 Tor 的攻击相比,我们的攻击更加准确并且需要更少的资源。
Anonymity systems such as Tor aim to enable users to communicate in a manner that is untraceable by adversaries that control a small number of machines. To provide efficient service to users, these anonymity systems make full use of forwarding capacity when sending traffic between intermediate relays. In this paper, we show that doing this leaks information about the set of Tor relays in a circuit (path). We present attacks that, with high confidence and based solely on throughput information, can (a) reduce the attacker's uncertainty about the bottleneck relay of any Tor circuit whose throughput can be observed, (b) exactly identify the guard relay(s) of a Tor user when circuit throughput can be observed over multiple connections, and (c) identify whether two concurrent TCP connections belong to the same Tor user, breaking unlinkability. Our attacks are stealthy, and cannot be readily detected by a user or by Tor relays. We validate our attacks using experiments over the live Tor network. We find that the attacker can substantially reduce the entropy of a bottleneck relay distribution of a Tor circuit whose throughput can be observed-the entropy gets reduced by a factor of 2 in the median case. Such information leaks from a single Tor circuit can be combined over multiple connections to exactly identify a user's guard relay(s). Finally, we are also able to link two connections from the same initiator with a crossover error rate of less than 1.5% in under 5 minutes. Our attacks are also more accurate and require fewer resources than previous attacks on Tor.