An Active De-anonymizing Attack Against Tor Web Traffic

An Active De-anonymizing Attack Against Tor Web Traffic
复制标题

DOI:
10.23919/tst.2017.8195352
复制
发表时间:
2017-12
影响因子:
6.6
通讯作者:
Ming Yang;Xiaodan Gu;Zhen Ling;Changxin Yin;Junzhou Luo
Ming Yang;Xiaodan Gu;Zhen Ling;Changxin Yin;Junzhou Luo
中科院分区:
计算机科学2区
文献类型:
--
作者:
Ming Yang;Xiaodan Gu;Zhen Ling;Changxin Yin;Junzhou Luo

文献摘要

被引文献

相似文献

Tor被广泛用于隐藏用户正在访问的目标网站。一种针对Tor的去匿名化技术,被称为网站指纹攻击,旨在通过被动分析Tor客户端加密流量的模式来推断Tor客户端访问的网站。然而,HTTP管道和Tor电路复用技术可以通过在单个TCP连接中混合承载web对象的流量来影响攻击的准确性。在本文中,我们提出了一种新的主动网站指纹攻击,通过在第一跳Tor节点上识别和延迟HTTP请求。然后,我们可以分离携带不同web对象的流量,以获得更可区分的流量模式。为了实现这一目标,提出了基于统计分析和目标函数优化的两种算法来构建通用的分组延迟方案。我们在经验实验中对我们的主动攻击进行了评估,获得了98.64%的最高准确率,而被动攻击的准确率为85.95%。我们还在开放世界场景中进行实验。当k- nn分类器的参数k设为5时,我们可以得到真阳性率为90.96%,假阳性率为3.9%。
Tor is pervasively used to conceal target websites that users are visiting. A de-anonymization technique against Tor, referred to as website fingerprinting attack, aims to infer the websites accessed by Tor clients by passively analyzing the patterns of encrypted traffic at the Tor client side. However, HTTP pipeline and Tor circuit multiplexing techniques can affect the accuracy of the attack by mixing the traffic that carries web objects in a single TCP connection. In this paper, we propose a novel active website fingerprinting attack by identifying and delaying the HTTP requests at the first hop Tor node. Then, we can separate the traffic that carries distinct web objects to derive a more distinguishable traffic pattern. To fulfill this goal, two algorithms based on statistical analysis and objective function optimization are proposed to construct a general packet delay scheme. We evaluate our active attack against Tor in empirical experiments and obtain the highest accuracy of 98.64%, compared with 85.95% of passive attack. We also perform experiments in the open-world scenario. When the parameter k of k-NN classifier is set to 5, then we can obtain a true positive rate of 90.96% with a false positive rate of 3.9%.