信息安全研究 ›› 2024, Vol. 10 ›› Issue (12): 1100-.

• 综合安全防御体系专题 • 上一篇    下一篇

基于传入数据单元数量填充的网站指纹防御方法

黄斌杜彦辉   

  1. (中国人民公安大学信息网络安全学院北京100076)
  • 出版日期:2024-12-25 发布日期:2024-12-25
  • 通讯作者: 黄斌 博士研究生.主要研究方向为隐私保护、匿名通信、网络指纹. beenhuang@126.com
  • 作者简介:黄斌 博士研究生.主要研究方向为隐私保护、匿名通信、网络指纹. beenhuang@126.com 杜彦辉 博士,教授,博士生导师.主要研究方向为人工智能、大数据. duyanhui@ppsuc.edu.com

An Effective Website Fingerprinting Defense Utilizing Padding #br# Based on the Number of Incoming Cells#br#

Huang Bin and Du Yanhui   

  1. (College of Information and Cyber Security, People’s Public Security University of China, Beijing 100076)
  • Online:2024-12-25 Published:2024-12-25

摘要: Tor匿名网络是一种旨在保护用户通信隐私的匿名通信系统.然而,网站指纹攻击对用户通信隐私实施去匿名化,从而破坏用户的匿名性.为了防范网站指纹攻击,Tor项目组在其网络中设计部署了一种名为CPF(circuit padding framework)的网站指纹防御框架.然而,CPF防御框架的防御技术无法有效防范最优网站指纹攻击算法TikTok.为此,提出了基于传入数据单元数量填充的网站指纹防御算法BreakPad.在此基础上,在Tor网络中实现了2种填充机防御模型:August和October.填充机August采用了单向填充机制,而填充机October采用了双向填充机制.实验结果显示,相较于填充机RBB,填充机August少使用18%的带宽开销,将TikTok算法的真阳率进一步降低了2.4%(从80.55%降到78.15%),而填充机October少使用11%的带宽开销,将TikTok算法的真阳率进一步降低了11.3%(从80.55%降到69.25%).这些结果表明,BreakPad算法能有效防御最优攻击算法TikTok,且其防御性能优于CPF防御框架的防御技术.

关键词: 隐私保护, 匿名通信, Tor, 网站指纹, 防御

Abstract: Tor is an anonymity system that protects users’ online privacy. However, website fingerprinting (WF) attacks can deanonymize users’ privacy and thus destroy their anonymity protected by Tor. In response, the Tor community has deployed a WF defense framework, called Circuit Padding Framework (CPF) in the Tor network. However, the defense techniques of the CPF framework cannot effectively prevent the most advanced website fingerprinting attack algorithm, TikTok. In this paper, we propose a novel WF defense called BreakPad. Based on BreakPad, we implemented two padding machines called August and October. August is a oneway padding machine, and October is a twoway padding machine. Our results show that, compared to the best padding machine RBB, August, with 18% less bandwidth overhead, further reduces TikTok’s TPR by 2.4%, and October, with 11% less bandwidth overhead, further reduces TikTok’s TPR by 11.3%. The results show that BreakPad is effective against TikTok and outperforms CPF.

Key words: privacy, anonymity system, Tor, website fingerprinting, defense

中图分类号: