Chaff Allocation and Performance for Network Traffic Obfuscation
Ertuğrul Necdet Çiftçioğlu, Rommie L. Hardy, Kevin Chan, Lisa Scott, Diego F. M. Oliveira, Gunjan Verma · 2018
This work considers performance analysis of chaff-based traffic obfuscation against a passive adversary aiming to obtain contextual information, e.g. such as the protocol being used. The obfuscation could be either in terms of chaff bytes which are dummy bytes appended to packets of the intended traffic stream, or chaff packets which are dummy packets again inserted in specific intervals of the original packet stream. Despite consisting of dummy bytes, chaff deployment still results in additional resource consumption and potential drawbacks, and hence has to be deployed in a controlled manner. We first define notions of vulnerability of traffic patterns in terms of contextual privacy. Next, we fix the adversary and focus on optimal allocation of the chaff resources among the traffic to be obfuscated. For adversaries which perform statistical characterization based on packet sizes and interarrival times, we derive chaff placement algorithms based on the waterfilling algorithm commonly used in the field of information theory. We apply our derived algorithms to representative real-world scenarios to obfuscate certain applications vulnerable to contextual privacy leakage.