arrow
返回

An Active De-anonymizing Attack Against Tor Web Traffic

delete2017-12-01
delete12
delete
OA
AI
杨
杨明 (Ming Yang) *
顾
顾晓丹 (Xiaodan Gu)
Z
Zhen Ling
C
Changxin Yin
罗
罗军舟 (Junzhou Luo)
DOI:10.23919/TST.2017.8195352delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Tor is pervasively used to conceal target websites that users are visiting. A de-anonymization technique against Tor, referred to as website fingerprinting attack, aims to infer the websites accessed by Tor clients by passively analyzing the patterns of encrypted traffic at the Tor client side. However, HTTP pipeline and Tor circuit multiplexing techniques can affect the accuracy of the attack by mixing the traffic that carries web objects in a single TCP connection. In this paper, we propose a novel active website fingerprinting attack by identifying and delaying the HTTP requests at the first hop Tor node. Then, we can separate the traffic that carries distinct web objects to derive a more distinguishable traffic pattern. To fulfill this goal, two algorithms based on statistical analysis and objective function optimization are proposed to construct a general packet delay scheme. We evaluate our active attack against Tor in empirical experiments and obtain the highest accuracy of 98.64%, compared with 85.95% of passive attack. We also perform experiments in the open-world scenario. When the parameter k of k-NN classifier is set to 5, then we can obtain a true positive rate of 90.96% with a false positive rate of 3.9%.
Keyword:
traffic analysis
active website fingerprinting
anonymous communication
Tor
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

T
Tsinghua Science and Technology
IF:
3.5
论文数:
987
被引数:
2.5K

机构

S
southeast university - china
学者数:
5.3W
论文数: 4.9W
被引数: 57
引用论文

引用论文

暂无论文信息