Privacy-preserving traffic padding in web-based applications
Wen Ming Liu, Lingyu Wang, Pengsu Cheng, Mourad Debbabi · 2011
While web-based applications are gaining popularity, they also pose new security challenges. In particular, Chen et al. recently revealed that many popular Web applications actually leak out highly sensitive data from encrypted traffic due to side-channel attacks using packet sizes and timing [1]. They further demonstrated that existing solutions usually incur a high overhead while still not guaranteeing privacy protection. In this paper, we observe a striking similarity between this issue and another well studied problem, privacy-preserving data publishing (PPDP). Based on such a similarity, we propose a formal model for privacy-preserving traffic padding (PPTP) that encompasses privacy requirement, padding cost, and padding methods.