Simple and compact flow fingerprinting robust to transit through low-latency anonymous networks

Xue Yang, Eugene Y. Vasserman · 2016

This paper presents PIVOT, a new flow fingerprinting scheme for identifying websites visited by a user of a low-latency anonymous communication system. The adversary is difficult to detect, as data collection is fully passive and can be performed at the server-side, client-side, or anywhere along the packet path. Further, data analysis can be performed in real time or offline, as long as flow information can be stored. The fingerprint is composed of a combination of traffic volume and timing information, and can be represented and stored in a compact format. PIVOT can be implemented using weaker adversary models than previous fingerprinting schemes and can identify websites within a multi-website browsing session, i.e., the user is vulnerable even when employing cover traffic and/or browsing multiple websites. The design is efficient, easy to implement, requires only passive network monitoring, and is robust to most active defenses against flow fingerprinting, additional bandwidth utilization by the user, as well as alteration in packet size and packet frequency introduced by one-hop anonymizing proxies or multi-hop anonymity systems such as Tor. We implement PIVOT and validate its accuracy against the Anonymizer.com one-hop proxy and the Tor browser bundle, using browsing patterns that better match real human behavior than those in the previous literature. Results indicate that end-to-end unlinkability can be broken with modest processing power and network capacity requirements, even if the target flow has been repacketized and combined with other flows.

Read the paper · More papers on PaperTik