Bayes, not Naïve: Security Bounds on Website Fingerprinting Defenses

Bayes, not Naïve: Security Bounds on Website Fingerprinting Defenses
复制标题

贝叶斯,而不是朴素:网站指纹防御的安全界限

DOI:
10.1515/popets-2017-0046
复制
发表时间:
2017
影响因子:
--
通讯作者:
Giovanni Cherubin
Giovanni Cherubin
中科院分区:
--
文献类型:
--
作者:
Giovanni Cherubin

文献摘要

被引文献

相似文献

摘要网站指纹(WF)攻击引起了人们对用户隐私的严重关注。他们采用机器学习(ML)技术,允许本地被动攻击者发现用户的Web浏览行为,即使她通过加密隧道(例如Tor,VPN)浏览。过去已经提出了许多防御措施;然而,通常很难对其安全性进行正式保证,这通常是针对最先进的攻击进行经验评估。在本文中,我们提出了一个实用的方法来获得任何WF防御的安全界限,其中的界限取决于一个选定的功能集。这个结果来自于将WF攻击减少到ML分类任务,在ML分类任务中,我们可以确定最小的可实现错误(贝叶斯错误)。这样的误差可以在实践中估计,并且对于WF对手来说,对于他可能使用的任何分类算法来说都是下限。我们的工作有两个主要的结果:i)它允许确定WF防御的安全性,在一个黑盒子的方式,相对于国家的最先进的功能集和ii)它有利于转移未来WF研究的重点,以确定最佳的功能集。这种方法的一般性进一步表明,该方法可以用来定义其他ML为基础的攻击的安全界限。
Abstract Website Fingerprinting (WF) attacks raise major concerns about users’ privacy. They employ Machine Learning (ML) techniques to allow a local passive adversary to uncover the Web browsing behavior of a user, even if she browses through an encrypted tunnel (e.g. Tor, VPN). Numerous defenses have been proposed in the past; however, it is typically difficult to have formal guarantees on their security, which is most often evaluated empirically against state-of-the-art attacks. In this paper, we present a practical method to derive security bounds for any WF defense, where the bounds depend on a chosen feature set. This result derives from reducing WF attacks to an ML classification task, where we can determine the smallest achievable error (the Bayes error). Such error can be estimated in practice, and is a lower bound for a WF adversary, for any classification algorithm he may use. Our work has two main consequences: i) it allows determining the security of WF defenses, in a black-box manner, with respect to the state-of-the-art feature set and ii) it favors shifting the focus of future WF research to identifying optimal feature sets. The generality of this approach further suggests that the method could be used to define security bounds for other ML-based attacks.