• DocumentCode
    1358925
  • Title

    Correlation-Based Traffic Analysis Attacks on Anonymity Networks

  • Author

    Zhu, Ye ; Fu, Xinwen ; Graham, Brian ; Bettati, Riccardo ; Zhao, Wei

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Cleveland State Univ., Cleveland, OH, USA
  • Volume
    21
  • Issue
    7
  • fYear
    2010
  • fDate
    7/1/2010 12:00:00 AM
  • Firstpage
    954
  • Lastpage
    967
  • Abstract
    In this paper, we address attacks that exploit the timing behavior of TCP and other protocols and applications in low-latency anonymity networks. Mixes have been used in many anonymous communication systems and are supposed to provide countermeasures to defeat traffic analysis attacks. In this paper, we focus on a particular class of traffic analysis attacks, flow-correlation attacks, by which an adversary attempts to analyze the network traffic and correlate the traffic of a flow over an input link with that over an output link. Two classes of correlation methods are considered, namely time-domain methods and frequency-domain methods. Based on our threat model and known strategies in existing mix networks, we perform extensive experiments to analyze the performance of mixes. We find that all but a few batching strategies fail against flow-correlation attacks, allowing the adversary to either identify ingress and egress points of a flow or to reconstruct the path used by the flow. Counterintuitively, some batching strategies are actually detrimental against attacks. The empirical results provided in this paper give an indication to designers of Mix networks about appropriate configurations and mechanisms to be used to counter flow-correlation attacks.
  • Keywords
    Internet; computer network security; correlation methods; frequency-domain analysis; telecommunication traffic; time-domain analysis; TCP; correlation-based traffic analysis attacks; flow-correlation attacks; frequency-domain methods; low-latency anonymity networks; time-domain methods; Privacy; anonymity; anonymous communication; flow-correlation attack.; mixes;
  • fLanguage
    English
  • Journal_Title
    Parallel and Distributed Systems, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1045-9219
  • Type

    jour

  • DOI
    10.1109/TPDS.2009.146
  • Filename
    5226624