A novel application classification attack against Tor

A novel application classification attack against Tor
复制标题

DOI:
10.1002/cpe.3593
复制
发表时间:
2015-12
期刊:
Concurrency and Computation: Practice and Experience
影响因子:
--
通讯作者:
Gaofeng He;Ming Yang;Junzhou Luo;Xiaodan Gu
Gaofeng He;Ming Yang;Junzhou Luo;Xiaodan Gu
中科院分区:
其他
文献类型:
--
作者:
Gaofeng He;Ming Yang;Junzhou Luo;Xiaodan Gu

文献摘要

相似文献

Tor是一个著名的匿名通信系统,用于保护用户的在线隐私。它支持TCP应用程序,并将上层应用程序数据打包到加密的等大小单元中,使用洋葱路由隐藏用户的隐私信息。然而,我们注意到,目前的Tor设计无法隐藏某些应用程序行为。例如,P2P应用程序通常同时上传和下载文件,这种行为特征也保留在Tor流量中。受此影响,我们研究了一种新的针对Tor的攻击,应用程序分类攻击,它可以从Tor流量中识别应用程序类型。攻击者首先仔细选择一些流特征,如突发量和方向来表示应用程序行为,并利用一些有效的机器学习算法(例如,Profile Hidden Markov Model)来模拟不同类型的应用程序。然后他或她可以使用这些建立的模型来分类目标的Tor流量并推断其应用类型。利用并行计算技术实现了对Tor的应用分类攻击,实验验证了该攻击的可行性和有效性。我们认为,应用程序类型信息的披露是对Tor用户匿名性的严重威胁,因为它可以用来减少匿名集,并促进其他攻击。我们还提出了指导方针,以抵御应用程序分类攻击。版权所有© 2015约翰威利父子有限公司.
Tor is a famous anonymous communication system for preserving users' online privacy. It supports TCP applications and packs upper‐layer application data into encrypted equal‐sized cells with onion routing to hide private information of users. However, we note that the current Tor design cannot conceal certain application behaviors. For example, P2P applications usually upload and download files simultaneously, and this behavioral feature is also kept in Tor traffic. Motivated by this observation, we investigate a new attack against Tor, application classification attack, which can recognize application types from Tor traffic. An attacker first carefully selects some flow features such as burst volumes and directions to represent the application behaviors and takes advantage of some efficient machine‐learning algorithm (e.g., Profile Hidden Markov Model) to model different types of applications. Then he or she can use these established models to classify target's Tor traffic and infer its application type. We have implemented the application classification attack on Tor using parallel computing, and our experiments validate the feasibility and effectiveness of the attack. We argue that the disclosure of application type information is a serious threat to Tor users' anonymity because it can be used to reduce the anonymity set and facilitate other attacks. We also present guidelines to defend against application classification attack. Copyright © 2015 John Wiley & Sons, Ltd.