Understanding the Privacy-Preserving Potential of HTTP/2 Against Webpage Fingerprinting
Bogdan Constantin Cebere, Prateek Kumar, Sylvain Chatel, Wouter Lueks, Christian Rossow
Abstract
Website fingerprinting (WF) attacks can infer which webpage a user visits from encrypted HTTPS traffic alone, compromising privacy even without decryption. WF defenses commonly shape traffic through noise, padding, delays, or flow splitting -yet they are most often studied from the perspective of encapsulating protocols like Tor or VPN rather than at the application layer (HTTP).
In this work, we focus on application-layer defenses enabled by the most widely deployed version of HTTP -HTTP/2. We demonstrate how known defenses can be emulated through HTTP/2 features at the client side (HTTPOS, LLaMA, FRONT, Tamaraw) and the server side (ALPaCA, Tamaraw). We further show that HTTP/2 features -such as proactive resource suggestion, multiplexing, and flow control -offer untapped potential for lightweight yet effective defenses deployable at both endpoints.
We evaluate these defenses using a unified blueprint that calibrates defense parameters per dataset, then combines practical attacks, information-theoretic leakage estimates, and overhead measurements. For each defense, this framework identifies the strongest hyperparameter-tuned fingerprinting model and estimates the residual uncertainty induced by the defense using two information-theoretic leakage estimators -all while accounting for the defense's privacy-overhead trade-offs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 33a9fb1a-edd9-4f5c-bee8-a7e95c4363d7Builds on24
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 632 citations
- Website Fingerprinting at Internet ScaleAndriy Panchenko, Fabian Lanze, Jan Pennekamp, Thomas Engel et al.NDSS 2016 · 625 citations
- ET-BERT: A Contextualized Datagram Representation with Pre-training Transformers for Encrypted Traffic ClassificationXinjie Lin, Gang Xiong, Gaopeng Gou, Zhen Li et al.WWW 2022 · 490 citations
- Automated Website Fingerprinting through Deep LearningVera Rimmer, Davy Preuveneers, Marc Juarez, Tom van Goethem et al.NDSS 2018 · 399 citations
Related papers
- TrafficSliver: Fighting Website Fingerprinting Attacks with Traffic SplittingWladimir De la Cadena, Asya Mitseva, Jens Hiller, Jan Pennekamp et al.CCS 2020 · 110 citations
- QCSD: A QUIC Client-Side Website-Fingerprinting Defence FrameworkJean-Pierre Smith, Luca Dolfi, Prateek Mittal, Adrian PerrigUSENIX Security 2022
- Zero-delay Lightweight Defenses against Website FingerprintingJiajun Gong, Tao WangUSENIX Security 2020
- Walkie-Talkie: An Efficient Defense Against Passive Website Fingerprinting AttacksTao Wang, Ian GoldbergUSENIX Security 2017 · 249 citations
- Measuring Information Leakage in Website Fingerprinting Attacks and DefensesShuai Li, Huajun Guo, Nicholas HopperCCS 2018 · 97 citations
