A highly optimized flow-correlation attack
A highly optimized flow-correlation attack
复制标题
高度优化的流相关攻击
DOI:
--
复制
发表时间:
2013
期刊:
影响因子:
--
通讯作者:
F. Pérez
中科院分区:
文献类型:
--
作者:
J. Elices;F. Pérez
Abstract—Deciding that two network flows are essentiallythe same is an important problem in intrusion detection andin tracing anonymous connections. A stepping stone or ananonymity network may try to prevent flow correlation by addingchaff traffic, splitting the flow in several subflows or addingrandom delays. A well-known attack for these types of systems isactive watermarking. However, active watermarking systems canbe detected and an attacker can modify the flow in such a waythat the watermark is removed and can no longer be decoded.This leads to the two basic features of our scheme: a highly-optimized algorithm that achieves very good performance and apassive analysis that is undetectable.We propose a new passive analysis technique where detection isbased on Neyman-Pearson lemma. We correlate the inter-packetdelays (IPDs) from both flows. Then, we derive a modification todeal with stronger adversary models that add chaff traffic, splitthe flows or add random delays. We empirically validate thedetectors with a simulator. Afterwards, we create a watermark-based version of our scheme to study the trade-off betweenperformance and detectability. Then, we compare the results withother state-of-the-art traffic watermarking schemes in severalscenarios concluding that our scheme outperforms the rest.Finally, we present results using an implementation of ourmethod on live networks, showing that the conclusions can beextended to real-world scenarios.Our scheme needs only tens of packets under normal networkinterference and a few hundreds of packets when a number ofcountermeasures are taken.