基于侧信道分析的Web站点指纹识别技术研究
批准号:
62102084
项目类别:
青年科学基金项目(C类)
资助金额:
30.0 万元
负责人:
顾晓丹
依托单位:
学科分类:
网络与系统安全
结题年份:
2024
批准年份:
2021
项目状态:
已结题
项目参与者:
顾晓丹
中文摘要
匿名通信系统的广泛应用对网络监管造成了严峻挑战,而现有匿名Web流量分析技术在实用性方面存在诸多限制,研究提高其可用性具有重要现实意义。本项目拟基于侧信道分析,在大规模无特定目标、面向特定目标以及多页面流量混杂三种场景下,研究Web站点指纹识别方法,分别解决可扩展性、识别效果和适用性三方面的问题。提出基于持续学习的指纹识别方法,通过改进深度残差网络进行样本表征学习,并引入蒸馏损失实现类别增量更新,以提高可扩展性;设计基于强化学习的报文主动调制方案以获得更为清晰的流量特征,解决被动流量分析时特征模糊、易抖动的问题,进一步提高准确率;在存在背景流量情况下研究多页面匿名交叠流量解构方案,并设计基于局部序列匹配的片段化指纹识别方法,突破现有攻击模型局限性。在理论成果基础上开发可实际部署的指纹识别工具集。通过本项目的研究,将提升Web站点指纹攻击技术在实际场景中的可用性,为匿名流量监管提供技术支撑。
英文摘要
The widespread use of anonymous communication systems poses severe challenges to network supervision. However, the existing anonymous Web traffic analysis technologies have many limitations which restrict the practicability. Therefore, it is of great practical significance to improve its usability. This project intends to analyze the theory and method of website fingerprinting attack based on the side channel analysis technology under three practical scenarios of large-scale non-target, target-oriented and multi-tab, aiming at improving the scalability, accuracy and applicability respectively. We propose a novel website fingerprinting attack through lifelong learning, and design a sample representation learning method based on deep residual network. The distillation loss function is introduced to preserves knowledge of the original model, which improve the scalability while realizing class-incremental learning. Considering that the values of selected features are blur and prone to jitter in the passive attack model, an active website fingerprinting attack is studied to obtain clearer features and higher accuracy by modulating the request packets. To optimize the packet modulation, we generate the packet modulation scheme based on reinforcement learning. Furthermore, as for the solution of the poor applicability caused by severe assumptions, a website fingerprinting attack against multi-tab browsing behavior is proposed. To filter the background traffic, we design a decomposition method for anonymous overlapped traffic. Then we identify the segmented fingerprints based on local sequence matching. Finally, a set of website fingerprinting identification tools that can be practically deployed is developed. This project is able to improve the practicality of the website fingerprinting attack in the actual surveillance scenarios, which is expected to provide technical support for the surveillance of anonymous communication traffic.
Web站点指纹攻击是一种利用侧信道分析方法提取匿名/加密HTTP流量特征形成指纹从而识别用户所访问站点的技术。无论是从匿名通信流量监管,还是从加强通信隐私保护的角度,研究Web站点指纹攻击及防御技术具有重要现实意义。本项目针对现有攻击方法威胁模型限制过多、防御方法效率较低无法有效在线部署等问题,进行了以下三方面工作的研究:.(1)针对现有攻击模型假设过强导致适用性低的问题,研究面向多页面的Web站点指纹攻击方法。通过分析网络流量时序特征,构建网络流量分类模型,以区分单页面、多页面流量,并提取上行数据包相关特征生成数据集。考虑到存在样本不均衡的情况,设计基于BalanceCascade的多页面分割点识别算法,实现多页面流量分割,并分别构建基于残差网络以及多头自注意力机制的指纹识别模型对分割后的两段流量序列进行识别。.(2)针对现有防御方法带宽开销较大的问题,设计了基于遗传算法的流量特征整形技术,高效地搜索伪元数据包插入的位置和方向,以生成能欺骗网站指纹分类器的变异流量。利用遗传算法搜索技术,对原始需保护的流量随机执行一系列的变异操作以生成变异流量。为了更高效地搜索插入模式,利用了DF攻击模型提取流量中的高维度特征向量,并根据不同 Web站点间的特征向量间的距离,设计了适应度函数和变异方向控制机制以快速搜索需保护Web 站点流量的变异方向。.(3)针对现有防御方法难以在线部署的问题,在分析在线与离线防御场景差异的基础上,利用Grad-CAM算法确定流量序列的关键区域,并设计面向关键区域的非目标针对性白盒对抗补丁优化生成方案,实现对抗补丁的生成。在此基础上,设计对抗补丁注入方案实现在线网络流量整形,并评估了该防御方法的有效性。.综上所述,本项目通过对多页面网络流量分割并基于不同流量片段特性构建分类模型,实现了面向多页面的在线Web站点指纹攻击。通过深度学习模型提取的深度指纹特征设计遗传算法的适应度函数,实现了基于遗传算法的流量特征整形防御技术。利用Grad-CAM算法确定关键区域,在此基础上进行对抗补丁的生成和在线注入,实现了对Web站点指纹攻击的在线防御。
国内基金
海外基金