Browser Fingerprinting from Coarse Traffic Summaries: Techniques and Implications

Browser Fingerprinting from Coarse Traffic Summaries: Techniques and Implications
复制标题

粗略流量摘要中的浏览器指纹识别:技术和含义

DOI:
--
复制
发表时间:
2009
期刊:
International Conference on Detection of intrusions and malware, and vulnerability assessment
影响因子:
--
通讯作者:
M. Reiter
M. Reiter
中科院分区:
--
文献类型:
--
作者:
T. Yen;Xin Huang;F. Monrose;M. Reiter

文献摘要

被引文献

相似文献

我们演示了,仅使用进出主机的Web流量的粗略摘要,就可以被动地识别主机上使用的浏览器实现,并且具有显著的精确度和召回率。我们的技术使用的连接记录仅包含源和目的地址和端口、包和字节计数以及每个连接的开始和结束时间。此外,我们还提供了两个浏览器识别应用程序。首先,我们展示了如何扩展网络入侵检测系统来检测更广泛的恶意软件。其次,我们展示了Web浏览器身份识别对已匿名的流记录中网站的去匿名化的影响。
We demonstrate that the browser implementation used at a host can be passively identified with significant precision and recall, using only coarse summaries of web traffic to and from that host. Our techniques utilize connection records containing only the source and destination addresses and ports, packet and byte counts, and the start and end times of each connection. We additionally provide two applications of browser identification. First, we show how to extend a network intrusion detection system to detect a broader range of malware. Second, we demonstrate the consequences of web browser identification to the deanonymization of web sites in flow records that have been anonymized.