Machine Learning-Assisted Website Fingerprinting Attacks with Side-Channel Information: A Comprehensive Analysis and Characterization

Han Wang, Hossein Sayadi, Avesta Sasan, P. D. Sai Manoj, Setareh Rafatirad, Houman Homayoun · 2021

The World Wide Web has become an essential part of modern society over the last decade, where people acquire new knowledge, conduct businesses, and their daily tasks. Such transformation makes the users' website browsing history contains more sensitive information, like health condition, political interests, financial situations, etc. Some defense mechanisms such as SSH tunnels and anonymity networks (e.g., Tor) have been proposed to cope with the potential website behaviors leakage and enhance browsing security. Nevertheless, some recent studies have demonstrated the possibility of fingerprinting websites based on side-channel information such as cache usage, memory utilization, CPU activity, and hardware performance counters. Such attacks observe the side-channel information and leverage effective machine learning techniques to infer which website a user is visiting via anonymity networks and encrypted proxies. Passive execution and extensive use of such side channels make the detection and mitigation of such side-channel information leakage-based fingerprinting attacks more challenging. This work presents a comprehensive analysis of state-of-the-art research on applying machine learning techniques on various side-channel features to develop effective website fingerprinting attacks.

Read the paper · More papers on PaperTik