Conjure: Summoning Proxies from Unused Address Space

Conjure: Summoning Proxies from Unused Address Space
复制标题

DOI:
10.1145/3319535.3363218
复制
发表时间:
2019-11
期刊:
Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Sergey Frolov;Jack Wampler;Sze Chuen Tan;J. A. Halderman;N. Borisov;Eric Wustrow
Sergey Frolov;Jack Wampler;Sze Chuen Tan;J. A. Halderman;N. Borisov;Eric Wustrow
中科院分区:
其他
文献类型:
--
作者:
Sergey Frolov;Jack Wampler;Sze Chuen Tan;J. A. Halderman;N. Borisov;Eric Wustrow

文献摘要

被引文献

相似文献

折射网络(以前称为“诱饵路由”)已经成为规避互联网审查的有前途的下一代方法。代理功能不是试图隐藏个人规避代理服务器免受审查,而是在网络的核心,在友好国家的合作ISP中实现。通过这些ISP的任何连接都可能成为信息自由流动的管道,因此审查人员无法在不阻止许多合法网站的情况下轻易阻止访问。虽然一个折射方案,TapDance,最近已经部署在ISP规模,它遭受了几个问题:有限数量的“诱饵”网站在现实的部署,高技术复杂性,以及不受欢迎的性能和可观察性之间的权衡审查。这些挑战可能会阻碍更广泛的部署,并最终允许审查人员阻止此类技术。我们提出了Conjure,一种改进的折射网络方法,通过利用未使用的地址空间在部署ISP克服了这些限制。我们的方案没有使用真实的网站作为代理连接的诱饵目的地,而是连接到没有Web服务器的IP地址,从网络的核心利用代理功能。审查员很难将这些幻影主机与真实的主机区分开来,但客户端可以将其用作代理。我们定义的Conjure协议,分析其安全性,并使用ISP测试床的原型进行评估。我们的研究结果表明,Conjure可能比TapDance更难阻止,更易于维护和部署,并提供更好的网络性能。
Refraction Networking (formerly known as "Decoy Routing") has emerged as a promising next-generation approach for circumventing Internet censorship. Rather than trying to hide individual circumvention proxy servers from censors, proxy functionality is implemented in the core of the network, at cooperating ISPs in friendly countries. Any connection that traverses these ISPs could be a conduit for the free flow of information, so censors cannot easily block access without also blocking many legitimate sites. While one Refraction scheme, TapDance, has recently been deployed at ISP-scale, it suffers from several problems: a limited number of "decoy" sites in realistic deployments, high technical complexity, and undesirable tradeoffs between performance and observability by the censor. These challenges may impede broader deployment and ultimately allow censors to block such techniques. We present Conjure, an improved Refraction Networking approach that overcomes these limitations by leveraging unused address space at deploying ISPs. Instead of using real websites as the decoy destinations for proxy connections, our scheme connects to IP addresses where no web server exists leveraging proxy functionality from the core of the network. These phantom hosts are difficult for a censor to distinguish from real ones, but can be used by clients as proxies. We define the Conjure protocol, analyze its security, and evaluate a prototype using an ISP testbed. Our results suggest that Conjure can be harder to block than TapDance, is simpler to maintain and deploy, and offers substantially better network performance.