MUFFLER: Secure Tor Traffic Obfuscation with Dynamic Connection Shuffling and Splitting
Minjae Seo, Myoungsung You, Jaehan Kim, Taejune Park, Seungwon Shin, Jinwoo Kim
Abstract
Tor, a widely utilized privacy network, enables anonymous communication but is vulnerable to flow correlation attacks that deanonymize users by correlating traffic patterns from Tor's ingress and egress segments. Various defenses have been developed to mitigate these attacks; however, they have two critical limitations: (i) significant network overhead during obfuscation and (ii) a lack of dynamic obfuscation for egress segments, exposing traffic patterns to adversaries. In response, we introduce MUFFLER, a novel connection-level traffic obfuscation system designed to secure Tor egress traffic. It dynamically maps real connections to a distinct set of virtual connections between the final Tor nodes and targeted services, either public or hidden. This approach creates egress traffic patterns fundamentally different from those at ingress segments without adding intentional padding bytes or timing delays. The mapping of real and virtual connections is adjusted in real-time based on ongoing network conditions, thwarting adversaries' efforts to detect egress traffic patterns. Extensive evaluations show that MUFFLER mitigates powerful correlation attacks with a TPR of 1% at an FPR of 10 -2 while imposing only a 2.17% bandwidth overhead. Moreover, it achieves up to 27x lower latency overhead than existing solutions and seamlessly integrates with the current Tor architecture.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4d9a4afc-becc-446d-b58f-cf790c2be102Builds on13
- DeepCorr: Strong Flow Correlation Attacks on Tor Using Deep LearningMilad Nasr, Alireza Bahramali, Amir HoumansadrCCS 2018 · 187 citations
- Defeating DNN-Based Traffic Analysis Systems in Real-Time With Blind Adversarial PerturbationsMilad Nasr, Alireza Bahramali, Amir HoumansadrUSENIX Security 2021 · 142 citations
- TrafficSliver: Fighting Website Fingerprinting Attacks with Traffic SplittingWladimir De la Cadena, Asya Mitseva, Jens Hiller, Jan Pennekamp et al.CCS 2020 · 110 citations
- Inside Job: Applying Traffic Analysis to Measure Tor from WithinRob Jansen, Marc Juarez, Rafa Gálvez, Tariq Elahi et al.NDSS 2018 · 86 citations
- SPRIGHT: extracting the server from serverless computing! high-performance eBPF-based event-driven, shared-memory processingShixiong Qi, Leslie Monis, Ziteng Zeng, Ian-Chin Wang et al.SIGCOMM 2022 · 85 citations
Related papers
- DeepCoFFEA: Improved Flow Correlation Attacks on Tor via Metric Learning and AmplificationSe Eun Oh, Taiji Yang, Nate Mathews, James K. Holland et al.S&P 2022 · 60 citations
- SoK: A Critical Evaluation of Efficient Website Fingerprinting DefensesNate Mathews, James K. Holland, Se Eun Oh, Mohammad Saidur Rahman et al.S&P 2023
- The Effect of DNS on Tor's AnonymityBenjamin Greschbach, Tobias Pulls, Laura M. Roberts, Philipp Winter et al.NDSS 2017 · 51 citations
- Duplicate-Node Attack: Identifying Guards to Degrade and Triangulate Onion ServicesChunmian Wang, Xiaodan Gu, Ming Yang, Qi Chen et al.INFOCOM 2026
- MirageFlow: A New Bandwidth Inflation Attack on TorChristoph Sendner, Jasper Stang, Alexandra Dmitrienko, Raveen Wijewickrama et al.NDSS 2024
