当前位置: X-MOL 学术J. Cloud Comp. › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
RBP: a website fingerprinting obfuscation method against intelligent fingerprinting attacks
Journal of Cloud Computing ( IF 3.418 ) Pub Date : 2021-05-20 , DOI: 10.1186/s13677-021-00244-8
Tao Luo , LiangMin Wang , ShangNan Yin , Hao Shentu , Hui Zhao

Edge computing has developed rapidly in recent years due to its advantages of low bandwidth overhead and low delay, but it also brings challenges in data security and privacy. Website fingerprinting (WF) is a passive traffic analysis attack that threatens website privacy which poses a great threat to user’s privacy and web security. It collects network packets generated while a user accesses website, and then uses a series of techniques to discover patterns of network packets to infer the type of website user accesses. Many anonymous networks such as Tor can meet the need of hide identity from users in network activities, but they are also threatened by WF attacks. In this paper, we propose a website fingerprinting obfuscation method against intelligent fingerprinting attacks, called Random Bidirectional Padding (RBP). It is a novel website fingerprinting defense technology based on time sampling and random bidirectional packets padding, which can covert the real packets distribution to destroy the Inter-Arrival Time (IAT) features in the traffic sequence and increase the difference between the datasets with random bidirectional virtual packets padding. We evaluate the defense against state-of-the-art website fingerprinting attacks in real scenarios, and show its effectiveness.

中文翻译:

RBP:一种用于智能指纹攻击的网站指纹混淆方法

边缘计算由于其低带宽开销和低延迟的优势,近年来发展迅速,但同时也带来了数据安全性和隐私性方面的挑战。网站指纹(WF)是一种被动的流量分析攻击,威胁网站的隐私,对用户的隐私和Web安全构成巨大威胁。它收集在用户访问网站时生成的网络数据包,然后使用一系列技术来发现网络数据包的模式以推断网站用户访问的类型。许多匿名网络(例如Tor)可以满足在网络活动中向用户隐藏身份的需求,但是它们也受到WF攻击的威胁。在本文中,我们提出了一种针对智能指纹攻击的网站指纹模糊处理方法,称为随机双向填充(RBP)。它是一种基于时间采样和随机双向数据包填充的新型网站指纹防御技术,可以掩盖真实数据包的分布,以破坏流量序列中的到达时间(IAT)功能,并通过随机双向数据集增加数据集之间的差异虚拟数据包填充。我们评估了在实际情况下针对最先进的网站指纹攻击的防御能力,并展示了其有效性。
更新日期:2021-05-22
down
wechat
bug