Traffic analysis of anonymity systems

Traffic analysis of anonymity systems
复制标题

DOI:
--
复制
发表时间:
2010
期刊:
--
影响因子:
--
通讯作者:
Ryan Craven
Ryan Craven
中科院分区:
其他
文献类型:
--
作者:
Ryan Craven

文献摘要

被引文献

相似文献

这项研究应用模式识别中的统计方法来测试互联网上使用的一种非常流行的匿名工具Tor的隐私能力。使用最近开发的称为因果状态分裂和重建(CSSR)的算法,我们可以创建通过Tor代理的网络过程的隐马尔可夫模型。与其他技术相比,我们的CSSR扩展创建一个最小熵模型,而无需任何先验知识的底层状态结构。Tor保存的网络过程的分组间时间延迟可以符号化为范围并用于构建模型。在构建训练模型之后,使用置信区间进行检测。新的测试数据可以通过模型来确定间隔并估计数据与模型的匹配程度。如果找到匹配,则可以使用状态序列或路径来唯一地描述关于模型的数据。通过比较这些路径,可以识别Tor用户。使用Tor网络的任何两台计算机的数据包数据可以与模型匹配,并且可以比较它们的状态序列,以给出两个系统实际上通过Tor进行通信的统计可能性。我们在私有Tor网络上进行实验来验证这一点。结果表明,在我们的测试场景中,通信系统可以被识别出95%的准确率。这种攻击与以前基于最大似然的方法不同,因为它可以在使用Tor的两台计算机之间执行。对手不需要成为全球观察者。如果已经构建了匹配模型,也可以实时执行攻击。
This research applies statistical methods in pattern recognition to test the privacy capabilities of a very popular anonymity tool used on the Internet known as Tor. Using a recently developed algorithm known as Causal State Splitting and Reconstruction (CSSR), we can create hidden Markov models of network processes proxied through Tor. In contrast to other techniques, our CSSR extensions create a minimum entropy model without any prior knowledge of the underlying state structure. The inter-packet time delays of the network process, preserved by Tor, can be symbolized into ranges and used to construct the models. After the construction of training models, detection is performed using Confidence Intervals. New test data can be fed through a model to determine the intervals and estimate how well the data matches the model. If a match is found, the state sequence, or path, can be used to uniquely describe the data with respect to the model. It is by comparing these paths that Tor users can be identified. Packet data from any two computers using the Tor network can be matched to a model and their state sequences can be compared to give a statistical likelihood that the two systems are actually communicating together over Tor. We perform experiments on a private Tor network to validate this. Results showed that communicating systems could be identified with a 95% accuracy in our test scenario. This attack differs from previous maximum likelihood-based approaches in that it can be performed between just two computers using Tor. The adversary does not need to be a global observer. The attack can also be performed in real-time provided that a matching model had already been constructed.