I Still Know What You Did Last Summer: Inferring Sensitive User Activities on Messaging Applications Through Traffic Analysis

I Still Know What You Did Last Summer: Inferring Sensitive User Activities on Messaging Applications Through Traffic Analysis
复制标题

DOI:
10.1109/tdsc.2022.3218191
复制
发表时间:
2023-09
影响因子:
7.3
通讯作者:
Ardavan Bozorgi;Alireza Bahramali;Fateme Rezaei;Amirhossein Ghafari;Amir Houmansadr;Ramin Soltani;D. Goeckel;D. Towsley
Ardavan Bozorgi;Alireza Bahramali;Fateme Rezaei;Amirhossein Ghafari;Amir Houmansadr;Ramin Soltani;D. Goeckel;D. Towsley
中科院分区:
计算机科学2区
文献类型:
--
作者:
Ardavan Bozorgi;Alireza Bahramali;Fateme Rezaei;Amirhossein Ghafari;Amir Houmansadr;Ramin Soltani;D. Goeckel;D. Towsley

文献摘要

被引文献

相似文献

即时通讯(IM)应用程序,如信号,电报和WhatsApp近年来已经变得非常流行。不幸的是,这种IM服务已经成为政府监视和审查的目标,因为这些服务是关于社会和政治敏感话题的公共和私人通信的所在地。为了保护他们的客户,流行的IM服务部署了最先进的加密技术。尽管使用先进的加密,我们表明,流行的IM应用程序泄漏的敏感信息,他们的客户端的对手只是监视他们的加密IM流量,没有必要利用任何软件漏洞的IM应用程序。具体来说,我们设计了流量分析攻击,使对手能够识别目标IM通信的参与者(例如,论坛),具有较高的准确性。我们认为,我们的研究表明,这类服务的用户面临着重大的现实威胁。我们证明了我们的攻击的实用性,通过对现实世界的IM通信广泛的实验。我们表明,标准的对策技术可以降低这些攻击的有效性。我们希望我们的研究将鼓励IM提供商将有效的流量混淆集成到他们的软件中。同时,我们设计了一个对抗系统,称为IMProxy,可以使用IM客户端,而不需要任何支持,从IM供应商。我们通过仿真和实验证明了IMProxy的有效性。
Instant Messaging (IM) applications such as Signal, Telegram, and WhatsApp have become tremendously popular in recent years. Unfortunately, such IM services have been targets of governmental surveillance and censorship, as these services are home to public and private communications on socially and politically sensitive topics. To protect their clients, popular IM services deploy state-of-the-art encryption. Despite the use of advanced encryption, we show that popular IM applications leak sensitive information about their clients to adversaries merely monitoring their encrypted IM traffic, with no need for leveraging any software vulnerabilities of IM applications. Specifically, we devise traffic analysis attacks enabling an adversary to identify participants of target IM communications (e.g., forums) with high accuracies. We believe that our study demonstrates a significant, real-world threat to the users of such services. We demonstrate the practicality of our attacks through extensive experiments on real-world IM communications. We show that standard countermeasure techniques can degrade the effectiveness of these attacks. We hope our study will encourage IM providers to integrate effective traffic obfuscation into their software. In the meantime, we have designed a countermeasure system, called IMProxy that can be used by IM clients with no need for any support from IM providers. We demonstrate the effectiveness of IMProxy through simulation and experiments.