课题基金 / 基金详情

基于公共匿名网络的隐私增强通信技术研究

批准号:
62072103
项目类别:
面上项目
资助金额:
57.0 万元
负责人:
杨明
依托单位:
学科分类:
网络与系统安全
结题年份:
2024
批准年份:
2020
项目状态:
已结题
项目参与者:
杨明

项目摘要

结项摘要

杨明的其他基金

相似基金

相关文献

中文摘要
利用公共匿名网络实现低成本但安全性增强的隐私通信具有重要意义。为了实现这个目标,需针对节点选择、路径构建、数据传输三个环节,并在批量和非批量数据传输两种应用场景下,解决恶意节点和敏感区域规避、多径传输匿名与性能平衡、基于匿名网络的高可用性隐蔽信道设计等问题。本项目拟从匿名网络和互联网路由层综合考虑节点静态、动态特性,设计敏感节点分类体系和通用识别方法实现匿名路径安全优化;引入加权门限秘密共享机制,设计数据拆分、路径分配和数据重组方案,实现批量数据多径传输的匿名和性能折衷平衡;建立通用框架支持基于第三方和非第三方匿名网络资源的隐蔽信道数据传输,设计信号编/解码方法和基于时变前导码的信道同步机制提高非批量数据传输的隐蔽性、容错性和高效性。基于上述技术开发可实际部署的隐私增强通信工具,研究成果不仅可用于普通用户的通信隐私保护,也可作为一种低成本、易使用的隐秘通信手段应用于公安、国安、国防等部门。
英文摘要
It is of great significance to realize low-cost but security-enhancing private communication based on the existing public anonymous communication networks. To fulfill this goal, it’s necessary to solve the problems of how to avoid malicious nodes and sensitive regions, how to achieve a tradeoff between anonymity and performance for multipath transmission, and how to design covert channels of high usability based on anonymous communication networks, focusing on relay node selection, anonymous path construction, and secure data transmission in two application scenarios of batch and non-batch data transmission. This project intends to comprehensively consider the static and dynamic characteristics of relay nodes from both the anonymous network and the Internet routing layer, design a taxonomy of sensitive nodes and a universal identification method, and thus optimize the security of the anonymous communication path. Also, after a weighted threshold secret sharing mechanism is introduced, and the data splitting, path assignment and data recovery schemes are designed and evaluated, the project aims to achieve a balance between anonymity and transmission performance, realizing the secure transmission of batch data based on multipath transmission. Furthermore, a general framework to support data transmission via covert channels based on both third-party and non-third-party anonymous network resources is established, signal encoding/decoding algorithms and channel synchronization based on time-varying preamble codes are designed to improve the invisibility, fault tolerance and efficiency of non-batch data transmission. Finally, a deployable privacy-enhancing communication tool will be developed employing above achievements. Not only can the research results be used to protect the communication privacy of ordinary network users, but they can also be applied in departments such as public security, national security and national defense as a low-cost and convenient private communication method.
基于现有的公共匿名网络实现低成本但安全性增强的隐私通信对于公安、国安、国防等部门具有重要意义。本项目在匿名网络测量和恶意节点识别的基础上,通过对匿名网络流量分析攻防的研究,利用多径传输和隐蔽通信机制设计并实现了架构于公共匿名网络之上、安全性增强的隐私通信工具。.在匿名网络测量和恶意节点识别方面,设计了一种Tor V3隐藏服务估计方案及系统,能自动收集服务域名并检测其服务状态,从而达到发现Tor核心网络的目的。为了避免使用攻击者部署的恶意隐藏服务目录服务器HSDir,通过定制蜜罐隐藏服务实现一对一和多对一的监测方案来识别Tor网络中的恶意HSDir,并对攻击者探测流进行了语义分析来分类判断攻击者的攻击意图,最终识别出8组32个恶意HSDir,发现25类探测模式以及3种主要的探测目的。在匿名网络流量分析攻防方面,提出了基于传输层有效负载长度分布的TPLD算法和基于主机行为与报文统计信息的HBSI算法,证明代理和OpenVPN转发的原始Tor流量和混淆Tor流量均具有很强的可识别性。在此基础上,设计了基于复合序列生成模型的Tor流量识别防御技术,并在Shadowsocks代理上部署验证了其可行性。进一步,本项目发现通过利用Freenet网络Path folding过程中的不一致协议行为漏洞和针对以太坊RPC调用的流量分析,可实现对Freenet下载者和以太坊RPC用户的去匿名化。在基于匿名网络的安全增强数据传输方面,提出了基于异常电路检验的Tor共谋节点识别方法,并利用聚类分析发现了Tor网络中四个聚集最为明显的簇,最终通过恶意节点和敏感区域规避设计了基于多径传输的批量数据安全传输机制。针对非批量数据的安全传输,通过构建虚拟隐藏服务并调制在不同HSDir上的域名状态,实现了基于隐藏服务域名状态的间接匿名隐蔽通信方案,信道容量最高可达150bps。.此外,项目组还开展了可信执行环境、SSL/TLS误用检测、节点设备缺陷发现等方面的工作。围绕上述工作,在包括CCS、NDSS、Security、INFOCOM在内的期刊和会议上发表论文25篇,其中CCF A类论文11篇、CCF B类论文7篇,获得ICDCS Distinguished Paper Award 1篇。
基于指纹攻击的网络实体识别技术研究
  • 批准号:
    61572130
  • 项目类别:
    面上项目
  • 资助金额:
    66.0万元
  • 批准年份:
    2015
  • 负责人:
    杨明
  • 依托单位:
交通土建工程中基于有机半导体g-C3N4的光催化降解NOx应用基础研究
  • 批准号:
    51208102
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    25.0万元
  • 批准年份:
    2012
  • 负责人:
    杨明
  • 依托单位:
基于侧信道攻击的匿名通信流量识别、分析和追踪技术研究
  • 批准号:
    61272054
  • 项目类别:
    面上项目
  • 资助金额:
    85.0万元
  • 批准年份:
    2012
  • 负责人:
    杨明
  • 依托单位:
基于主动流量分析的匿名通信追踪技术研究
  • 批准号:
    60903162
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    19.0万元
  • 批准年份:
    2009
  • 负责人:
    杨明
  • 依托单位:
国内基金
海外基金