• DocumentCode
    3600038
  • Title

    Inferring Application Type Information from Tor Encrypted Traffic

  • Author

    Gaofeng He ; Ming Yang ; Junzhou Luo ; Xiaodan Gu

  • Author_Institution
    China Electr. Power Res. Inst., Nanjing, China
  • fYear
    2014
  • Firstpage
    220
  • Lastpage
    227
  • Abstract
    Tor is a famous anonymity communication system for preserving users´ online privacy. It supports TCP applications and packs application data into encrypted equal-sized cells to hide some private information of users, such as the running application type (Web, P2P, FTP, Others). The known of application types is harmful because they can be used to reduce the anonymity set and facilitate other attacks. However, unfortunately, the current Tor design cannot conceal certain application behaviors. For example, P2P applications usually upload and download files simultaneously and this behavioral feature is also kept in Tor traffic. Motivated by this observation, we investigate a new attack against Tor, traffic classification attack, which can recognize application types from Tor traffic. An attacker first carefully selects some flow features, e.g., burst volumes and directions to represent the application behaviors and takes advantage of some efficient machine learning algorithm to model different types of applications. Then these established models can be used to classify target´s Tor traffic and infer its application type. We have implemented the traffic classification attack on Tor and our experiments validate the feasibility and effectiveness of the attack.
  • Keywords
    computer network security; cryptography; peer-to-peer computing; P2P applications; Tor design; Tor encrypted traffic; anonymity communication system; application type information; peer-to-peer applications; traffic classification attack; user online privacy preservation; Clustering algorithms; Computational modeling; Feature extraction; Hidden Markov models; Probability; Servers; Training; Tor; anonymous communication; privacy; profile HMM; traffic classification;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Cloud and Big Data (CBD), 2014 Second International Conference on
  • Print_ISBN
    978-1-4799-8086-4
  • Type

    conf

  • DOI
    10.1109/CBD.2014.37
  • Filename
    7176097