Obfs4 Traffic Identification Based on Multiple-feature Fusion

Obfs4 Traffic Identification Based on Multiple-feature Fusion
复制标题

基于多特征融合的Obfs4流量识别

DOI:
10.1109/icpics50287.2020.9202018
复制
发表时间:
2020
期刊:
2020 IEEE International Conference on Power, Intelligent Computing and Systems (ICPICS)
影响因子:
--
通讯作者:
Yongzhong He
Yongzhong He
中科院分区:
--
文献类型:
--
作者:
D. Liang;Yongzhong He

文献摘要

被引文献

相似文献

Tor是目前使用最多的匿名浏览器。用户可以通过Tor在互联网上进行匿名通信,一些犯罪分子可以使用Tor进行非法和犯罪活动。为了应对拥塞,Tor引入了桥接机制来取代以前的入口节点。Obfs4是Tor使用的最重要的网桥之一。它采用改进的椭圆曲线加密算法和随机填充来隐藏消息信息,抗检测能力极强。为了有效识别Obfs4流量,提出一种基于多特征融合的Obfs4流量识别方法。通过对Obfs4协议、数据包结构、节点发布策略、节点分布等方面的研究,提出了多种获取多特征的方法,包括随机性特征、顺序性特征、握手包长度特征、通信包统计特征等。此外,本文提出了一种基于加权高斯核函数的机器学习算法,该算法可以通过修改不同特征的权重来改变不同特征对最终分类结果的影响程度。最后通过实验确定了各特征的权重和算法所使用的参数。该算法的准确率为93.82%,召回率为99.00%,准确率为94.34%,大大优于本文提到的其他算法。同时,本文证明了Obfs4的匿名机制存在一定的漏洞,可以从其泄露的信息中获取其有效指纹来实施攻击。
Tor is currently the most used anonymous browser. Users can communicate anonymously on the Internet through Tor and some criminals can use Tor for illegal and criminal activities. In order to deal with congestion, Tor introduced a bridge mechanism to replace the previous ingress node. Obfs4 is one of the most important bridges used by Tor. It uses an improved elliptic curve encryption algorithm and random padding to hide message information, the anti-detection ability is extremely strong. In order to effectively identify Obfs4 traffic, this paper proposes a Obfs4 identification method based on Multiple-feature fusion. Through research on Obfs4 protocol, data packet structure, node publishing strategy, and node distribution, this paper proposes many ways to obtain multiple features, including randomness characteristics, sequential characteristics, handshake packet length characteristics, and communication packet statistics characteristics. In addition, this paper proposes a machine learning algorithm based on a weighted Gaussian kernel function, which can modify the weight of different features to change the degree of influence of different features on the final classification result. Finally, the weight of each feature and the parameters used by the algorithm are determined through experiments. The accuracy of the algorithm is 93.82%, the recall is 99.00%, and the accuracy is 94.34%, which is much better than other algorithms mentioned in this paper. At the same time, this paper proves that there are some loopholes in Obfs4's anonymity mechanism, and its effective fingerprint can be obtained from the information it leaks to carry out attacks.