Statistical identification of encrypted Web browsing traffic

作者: Qixiang Sun , D.R. Simon , Yi-Min Wang , W. Russell , V.N. Padmanabhan

DOI: 10.1109/SECPRI.2002.1004359

关键词:

摘要: Encryption is often proposed as a tool for protecting the privacy of World Wide Web browsing. However, encryption-particularly typically implemented in, or in concert with popular browsers-does not hide all information about encrypted plaintext. Specifically, HTTP object count and sizes are revealed (or at least incompletely concealed). We investigate identifiability traffic based on this unconcealed large sample pages, show that it suffices to identify significant fraction them quite reliably. also suggest some possible countermeasures against exposure kind experimentally evaluate their effectiveness.

参考文章(11)
David Goldschlag, Paul Syverson, Michael Reed, Onion Routing for Anonymous and Private Internet Connections ,(1999)
Oliver Berthold, Hannes Federrath, Stefan Köpsell, Web MIXes: a system for anonymous and unobservable Internet access privacy enhancing technologies. pp. 115- 129 ,(2001) , 10.1007/3-540-44702-4_7
Michael K. Reiter, Aviel D. Rubin, Crowds: anonymity for Web transactions ACM Transactions on Information and System Security. ,vol. 1, pp. 66- 92 ,(1998) , 10.1145/290163.290168
Charles Rackoff, Daniel R. Simon, Cryptographic defense against traffic analysis Proceedings of the twenty-fifth annual ACM symposium on Theory of computing - STOC '93. pp. 672- 681 ,(1993) , 10.1145/167088.167260
Venkata N. Padmanabhan, Lakshminarayanan Subramanian, An investigation of geographic mapping techniques for internet hosts Proceedings of the 2001 conference on Applications, technologies, architectures, and protocols for computer communications - SIGCOMM '01. ,vol. 31, pp. 173- 185 ,(2001) , 10.1145/383059.383073
Edward W. Felten, Michael A. Schneider, Timing attacks on Web privacy computer and communications security. pp. 25- 32 ,(2000) , 10.1145/352600.352606
Eran Gabber, Phillip B. Gibbons, David M. Kristol, Yossi Matias, Alain Mayer, Consistent, yet anonymous, Web access with LPWA Communications of The ACM. ,vol. 42, pp. 42- 47 ,(1999) , 10.1145/293411.293447
Paul Syverson, Gene Tsudik, Michael Reed, Carl Landwehr, Towards an analysis of onion routing security privacy enhancing technologies. pp. 96- 114 ,(2001) , 10.1007/3-540-44702-4_6
C. Molina-Jimenez, L. Marshall, True anonymity without mixes Proceedings. The Second IEEE Workshop on Internet Applications. WIAPP 2001. pp. 32- 40 ,(2001) , 10.1109/WIAPP.2001.941867