Obfs4 Traffic Identification Based on Multiple-feature Fusion
Obfs4 Traffic Identification Based on Multiple-feature Fusion
复制标题
基于多特征融合的Obfs4流量识别
DOI:
10.1109/icpics50287.2020.9202018
复制
发表时间:
2020
期刊:
影响因子:
--
通讯作者:
Yongzhong He
中科院分区:
文献类型:
--
作者:
D. Liang;Yongzhong He
Tor is currently the most used anonymous browser. Users can communicate anonymously on the Internet through Tor and some criminals can use Tor for illegal and criminal activities. In order to deal with congestion, Tor introduced a bridge mechanism to replace the previous ingress node. Obfs4 is one of the most important bridges used by Tor. It uses an improved elliptic curve encryption algorithm and random padding to hide message information, the anti-detection ability is extremely strong. In order to effectively identify Obfs4 traffic, this paper proposes a Obfs4 identification method based on Multiple-feature fusion. Through research on Obfs4 protocol, data packet structure, node publishing strategy, and node distribution, this paper proposes many ways to obtain multiple features, including randomness characteristics, sequential characteristics, handshake packet length characteristics, and communication packet statistics characteristics. In addition, this paper proposes a machine learning algorithm based on a weighted Gaussian kernel function, which can modify the weight of different features to change the degree of influence of different features on the final classification result. Finally, the weight of each feature and the parameters used by the algorithm are determined through experiments. The accuracy of the algorithm is 93.82%, the recall is 99.00%, and the accuracy is 94.34%, which is much better than other algorithms mentioned in this paper. At the same time, this paper proves that there are some loopholes in Obfs4's anonymity mechanism, and its effective fingerprint can be obtained from the information it leaks to carry out attacks.