Return
A practical multi-tab website fingerprinting attack
DOI:10.1016/j.jisa.2023.103627.png)
Abstract
En 中文
The rapid development of Internet of Things technology has allowed a massive number of devices to be connected, resulting in a lot of private data being transmitted over the network. To protect the security and privacy, anonymous communication technologies such as Tor are widely deployed. They use complex mechanisms such as encryption and multi-hop forwarding to hide the communication relationship and content. However, much existing work on the website fingerprinting attack has proven that there is still a risk of privacy disclosure. Website fingerprinting attacks can extract side channel information from encrypted traffic to form a fingerprint that identifies the victim's destination website. But most work is conducted in the ideal environments, assuming the absence of background traffic, which raises doubts about the effectiveness in the real world. In this paper, we relax the strong assumptions of the attack model and propose a practical multi-tab website fingerprinting attack. We first constructed a CNN model to distinguish whether the unknown traffic is generated by accessing a single web page or multiple web pages. Then we design a split point recognition method based on the BalanceCascade algorithm to separate the overlapping traffic. Furthermore, we build recognition models based on ResNet and multi-head self-attention mechanism to identify the tail-missing and head-overlapping traffic sequences respectively. Extensive experiments are carried out in the real-world scenario to evaluate the proposed method. When the time interval is randomly selected within 5-15s, we achieve an accuracy of 77.34% in split point recognition. And the accuracy of identifying the two pages is 88.19% and 63.02% respectively.
Keywords:
Website fingerprinting attack
Tor
Multi-tab
Traffic analysis
Journal
IF:
3.7
Papers:
1.9K
Citations:
4.9K

