Protecting against Website Fingerprinting with Multihoming

Protecting against Website Fingerprinting with Multihoming
复制标题

通过多宿主防御网站指纹识别

DOI:
10.2478/popets-2020-0019
复制
发表时间:
2020
影响因子:
--
通讯作者:
Patrick Thiran
Patrick Thiran
中科院分区:
--
文献类型:
--
作者:
Sébastien Henri;Gines Garcia;P. Serrano;A. Banchs;Patrick Thiran

文献摘要

参考文献

被引文献

相似文献

匿名通信工具,如Tor,被想要保持其网络活动私密性的用户广泛使用。但最近的研究表明,当一个本地的、被动的攻击者仅仅观察到数据包的时间戳、大小和方向(传入或传出)时,它仍然可以高精度地识别用户访问的网站。针对这些网站指纹攻击的几种防御措施已经提出,但它们的代价是流量和/或网站加载时间的显著开销。我们提出了一种防御网站指纹利用多归,其中用户可以通过多个网络发送流量访问互联网。使用多宿主,可以通过在网络之间分割流量来防止网站指纹,即通过从一个网络删除数据包并通过另一个网络发送数据包,而目前的防御只能添加数据包。这使我们能够设计一个没有流量开销的防御,正如我们通过对最先进攻击的广泛实验所展示的那样,达到与现有最佳实用防御相同的隐私水平。我们描述和评估了我们的防御的概念验证实现,并表明它不会增加显着的加载时间开销。我们的解决方案与其他最先进的防御系统兼容,并且我们表明,将它与另一种防御系统相结合可以进一步提高隐私。
Abstract Anonymous communication tools, such as Tor, are extensively employed by users who want to keep their web activity private. But recent works have shown that when a local, passive adversary observes nothing more than the timestamp, size and direction (incoming or outgoing) of the packets, it can still identify with high accuracy the website accessed by a user. Several defenses against these website fingerprinting attacks have been proposed but they come at the cost of a significant overhead in traffic and/or website loading time. We propose a defense against website fingerprinting which exploits multihoming, where a user can access the Internet by sending the traffic through multiple networks. With multihoming, it is possible to protect against website fingerprinting by splitting traffic among the networks, i.e., by removing packets from one network and sending them through another, whereas current defenses can only add packets. This enables us to design a defense with no traffic overhead that, as we show through extensive experimentation against state-of-the-art attacks, reaches the same level of privacy as the best existing practical defenses. We describe and evaluate a proof-ofconcept implementation of our defense and show that is does not add significant loading-time overhead. Our solution is compatible with other state-of-the-art defenses, and we show that combining it with another defense further improves privacy.
测量网站指纹攻击和防御中的信息泄漏
DOI: 10.1145/3243734.3243832
发表时间: 2018
期刊: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Li, Shuai;Guo, Huajun;Hopper, Nicholas
通讯作者: Hopper, Nicholas
DOI: 10.1145/3321705.3329802
发表时间: 2019-07
期刊: Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security
影响因子: --
作者:
Weiqi Cui;Tao Chen;C. Fields;Julian Chen;Anthony Sierra;Eric Chan-Tin
通讯作者: Weiqi Cui;Tao Chen;C. Fields;Julian Chen;Anthony Sierra;Eric Chan-Tin
DOI: --
发表时间: 2018-11
期刊: ArXiv
影响因子: --
作者:
A. Shusterman;Lachlan Kang;Yarden Haskal;Yosef Meltser;Prateek Mittal;Yossef Oren;Y. Yarom
通讯作者: A. Shusterman;Lachlan Kang;Yarden Haskal;Yosef Meltser;Prateek Mittal;Yossef Oren;Y. Yarom
p1-FP:利用深度学习提取、分类和预测网站指纹
DOI: 10.2478/popets-2019-0043
发表时间: 2019
影响因子: --
作者:
Oh, Se Eun;Sunkam, Saikrishna;Hopper, Nicholas
通讯作者: Hopper, Nicholas