A highly optimized flow-correlation attack

A highly optimized flow-correlation attack
复制标题

高度优化的流相关攻击

DOI:
--
复制
发表时间:
2013
期刊:
arXiv.org
影响因子:
--
通讯作者:
F. Pérez
F. Pérez
中科院分区:
--
文献类型:
--
作者:
J. Elices;F. Pérez

文献摘要

被引文献

相似文献

摘要判定两个网络flOW本质上相同是入侵检测和匿名连接跟踪中的一个重要问题。踏脚石或匿名网络可以尝试通过添加箔条Traffl_c、将fl_ow分成几个子fl_OW或添加随机延迟来防止IPv6_ow相关性。对这类系统的一种众所周知的攻击是主动水印。然而,主动水印系统是可以被检测到的,攻击者可以修改flow,使得水印被移除并且不能再被解码,这导致了该方案的两个基本特征:高度优化的算法获得了非常好的性能和不可检测的被动分析。我们将来自两个flOW的分组间延迟(IPD)关联起来。然后,我们推导出一个Modifi正离子来处理添加箔条陷阱fic、分裂flWS或添加随机延迟的较强对手模型。我们用模拟器对探测器进行了经验验证。然后,我们创建了一个基于水印的版本来研究性能和可检测性之间的权衡。然后,我们在几个场景下与其他现有的Traffic水印方案进行了比较,结果表明我们的方案优于其他方案;最后,我们通过在实时网络上的实现给出了结果,表明我们的结论可以扩展到真实世界的场景,在正常网络干扰下,我们的方案只需要几十个包,当采取一些对策时,我们的方案只需要几百个包。
Abstract—Deciding that two network flows are essentiallythe same is an important problem in intrusion detection andin tracing anonymous connections. A stepping stone or ananonymity network may try to prevent flow correlation by addingchaff traffic, splitting the flow in several subflows or addingrandom delays. A well-known attack for these types of systems isactive watermarking. However, active watermarking systems canbe detected and an attacker can modify the flow in such a waythat the watermark is removed and can no longer be decoded.This leads to the two basic features of our scheme: a highly-optimized algorithm that achieves very good performance and apassive analysis that is undetectable.We propose a new passive analysis technique where detection isbased on Neyman-Pearson lemma. We correlate the inter-packetdelays (IPDs) from both flows. Then, we derive a modification todeal with stronger adversary models that add chaff traffic, splitthe flows or add random delays. We empirically validate thedetectors with a simulator. Afterwards, we create a watermark-based version of our scheme to study the trade-off betweenperformance and detectability. Then, we compare the results withother state-of-the-art traffic watermarking schemes in severalscenarios concluding that our scheme outperforms the rest.Finally, we present results using an implementation of ourmethod on live networks, showing that the conclusions can beextended to real-world scenarios.Our scheme needs only tens of packets under normal networkinterference and a few hundreds of packets when a number ofcountermeasures are taken.