USENIX Security2021Top-tier venue
SiamHAN: IPv6 Address Correlation Attacks on TLS Encrypted Traffic via Siamese Heterogeneous Graph Attention Network
Tianyu Cui, Gaopeng Gou, Gang Xiong, Zhen Li, Mingxin Cui, Chang Liu
Abstract
Unlike IPv4 addresses, which are typically masked by a NAT, IPv6 addresses could easily be correlated with user activity, endangering their privacy. Mitigations to address this privacy concern have been deployed, making existing approaches for address-to-user correlation unreliable. This work demonstrates that an adversary could still correlate IPv6 addresses with users accurately, even with these protection mechanisms. To do this, we propose an IPv6 address correlation model - SiamHAN. The model uses a Siamese Heterogeneous Graph Attention Network to measure whether two IPv6 client addresses belong to the same user even if the user's traffic is protected by TLS encryption. Using a large real-world dataset, we show that, for the tasks of tracking target users and discovering unique users, the state-of-the-art techniques could achieve only 85% and 60% accuracy, respectively. However, SiamHAN exhibits 99% and 88% accuracy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 04b28c73-3455-430a-8a01-a60dd792a6b8Cited by top-tier papers5
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- CAT: Can Trust be Predicted with Context-Awareness in Dynamic Heterogeneous Networks?Jie Wang, Zheng Yan, Jiahe Lan, Xuyan Li et al.NDSS 2026 · 2 citations
- Understanding the Privacy-Preserving Potential of HTTP/2 Against Webpage FingerprintingBogdan Constantin Cebere, Prateek Kumar, Sylvain Chatel, Wouter Lueks et al.CCS 2026
- Interpretable and Robust Behavior Abstraction via Environment-Disentangled Heterogeneous GraphZhibin Ni, Hai Wan, Xibin ZhaoAAAI 2026
- Rosetta: Enabling Robust TLS Encrypted Traffic Classification in Diverse Network Environments with TCP-Aware Traffic AugmentationRenjie Xie, Jiahao Cao, Enhuan Dong, Mingwei Xu et al.USENIX Security 2023
Builds on7
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 632 citations
- Triplet Fingerprinting: More Practical and Portable Website Fingerprinting with N-shot LearningPayap Sirinam, Nate Mathews, Mohammad Saidur Rahman, Matthew WrightCCS 2019 · 268 citations
- DeepCorr: Strong Flow Correlation Attacks on Tor Using Deep LearningMilad Nasr, Alireza Bahramali, Amir HoumansadrCCS 2018 · 187 citations
- High Precision Open-World Website FingerprintingTao WangS&P 2020 · 95 citations
- Don't Forget to Lock the Back Door! A Characterization of IPv6 Network Security PolicyJakub Czyz, Matthew J. Luckie, Mark Allman, Michael D. BaileyNDSS 2016 · 87 citations
Related papers
- Graph Attention TrackingDongyan Guo, Yanyan Shao, Ying Cui, Zhenhua Wang et al.CVPR 2021
- WTAGRAPH: Web Tracking and Advertising Detection using Graph Neural NetworksZhiju Yang, Weiping Pei, Monchu Chen, Chuan YueS&P 2022 · 29 citations
- MT-FlowFormer: A Semi-Supervised Flow Transformer for Encrypted Traffic ClassificationRuijie Zhao, Xianwen Deng, Zhicong Yan, Jun Ma et al.KDD 2022 · 48 citations
- Hierarchical Attention Network with Correction for Cross-Domain User AssociationWenlong Liu, Ze Wang, Chenlong Wu, Yude Bai et al.AAAI 2026
- STGAT: Modeling Spatial-Temporal Interactions for Human Trajectory PredictionYingfan Huang, Huikun Bi, Zhaoxin Li, Tianlu Mao et al.ICCV 2019 · 615 citations
