Introducing Traffic Analysis
George Danezis, Richard Clayton · Auerbach Publications eBooks · 2007
Contents 5.1 Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .95 5.2 Military Roots . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .96 5.3 Civilian Traffic Analysis . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .99 5.4 Contemporary Computer and Communications Security . . . . . . . . . . 101 5.4.1 The Traffic Analysis of SSH . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 102 5.4.2 The Traffic Analysis of SSL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 103 5.4.3 Web Privacy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 103 5.4.4 Network Device Identification and Mapping . . . . . . . . . . . . . . . 104 5.4.5 Detecting Stepping Stones . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 106 5.5 Exploiting Location Data. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 106 5.6 Resisting Traffic Analysis on the Internet . . . . . . . . . . . . . . . . . . . . . . . . . . 107 5.7 Data Retention . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 110 5.8 Conclusion . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 112 References . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 112 5.1 Introduction In World War II, traffic analysis was used by the British at Bletchley Park to assess the size of Germany’s air force, and Japanese traffic analysis countermeasures contributed to the surprise of the 1941 attack on Pearl Harbor. Nowadays, Google uses the incidence of links to assess the relative importance of Web pages, credit card companies examine transactions to spot fraudulent patterns of spending, and amateur plane spotters revealed the CIA’s “extraordinary rendition” program. Diffie and Landau, in their book on wiretapping, went so far as to say that “traffic analysis, not cryptanalysis, is the backbone of communications intelligence” [1]. However, until recently the topic has been neglected by computer science academics. A rich literature discusses how to secure the confidentiality, integrity, and availability of communication content, but very little work has considered the information leaked from communications “traffic data” and how these compromises might be minimized.