ditto: WAN Traffic Obfuscation at Line Rate
Roland Meier, Vincent Lenders, Laurent Vanbever
Abstract
—Many large organizations operate dedicated wide area networks (WANs) distinct from the Internet to connect their data centers and remote sites through high-throughput links. While encryption generally protects these WANs well against content eavesdropping, they remain vulnerable to traffic analysis attacks that infer visited websites, watched videos or contents of VoIP calls from analysis of the traffic volume, packet sizes or timing information. Existing techniques to obfuscate Internet traffic are not well suited for WANs as they are either highly inefficient or require modifications to the communication protocols used by end hosts. This paper presents ditto , a traffic obfuscation system adapted to the requirements of WANs: achieving high-throughput traffic obfuscation at line rate without modifications of end hosts. ditto adds padding to packets and introduces chaff packets to make the resulting obfuscated traffic independent of production traffic with respect to packet sizes, timing and traffic volume. We evaluate a full implementation of ditto running on programmable switches in the network data plane. Our results show that ditto runs at 100 Gbps line rate and performs with negligible performance overhead up to a realistic traffic load of 70 Gbps per WAN link.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8f5d2830-81d1-4499-9727-bde8138879aaCited by top-tier papers5
- NetShaper: A Differentially Private Network Side-Channel Mitigation SystemAmir Sabzi, Rut Vora, Swati Goswami, Margo I. Seltzer et al.USENIX Security 2024 · 7 citations
- Minos : A Lightweight and Dynamic Defense against Traffic Analysis in Programmable Data PlanesZihao Wang, Qing Li, Guorui Xie, Dan Zhao et al.USENIX ATC 2025 · 4 citations
- A Hard-Label Black-Box Evasion Attack against ML-based Malicious Traffic Detection SystemsZixuan Liu, Yi Zhao, Zhuotao Liu, Qi Li et al.NDSS 2026 · 3 citations
- Defending against Traffic Analysis Attacks with Flexible In-Network ObfuscationGuorui Xie, Qing Li, Zhenning Shi, Gianni Antichi et al.NSDI 2026 · 2 citations
- MUFFLER: Secure Tor Traffic Obfuscation with Dynamic Connection Shuffling and SplittingMinjae Seo, Myoungsung You, Jaehan Kim, Taejune Park et al.INFOCOM 2025
Builds on6
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 632 citations
- k-fingerprinting: A Robust Scalable Website Fingerprinting TechniqueJamie Hayes, George DanezisUSENIX Security 2016 · 474 citations
- Walkie-Talkie: An Efficient Defense Against Passive Website Fingerprinting AttacksTao Wang, Ian GoldbergUSENIX Security 2017 · 249 citations
- Beauty and the Burst: Remote Identification of Encrypted Video StreamsRoei Schuster, Vitaly Shmatikov, Eran TromerUSENIX Security 2017 · 205 citations
- Programmable Calendar Queues for High-speed Packet SchedulingNaveen Kr. Sharma, Chenxingyu Zhao, Ming Liu, Pravein G. Kannan et al.NSDI 2020 · 119 citations
Related papers
- Encrypted DNS -> Privacy? A Traffic Analysis PerspectiveSandra Deepthy Siby, Marc Juarez, Claudia Díaz, Narseo Vallina-Rodriguez et al.NDSS 2020
- NetHide: Secure and Practical Network Topology ObfuscationRoland Meier, Petar Tsankov, Vincent Lenders, Laurent Vanbever et al.USENIX Security 2018 · 84 citations
- On Designing Secure Cross-user Redundancy Elimination for WAN OptimizationYuan Zhang, Ziwei Zhang, Minze Xu, Chen Tian et al.INFOCOM 2022 · 1 citation
- You Can Obfuscate, but You Cannot Hide: CrossPoint Attacks against Network Topology ObfuscationXuanbo Huang, Kaiping Xue, Lutong Chen, Mingrui Ai et al.USENIX Security 2024 · 10 citations
- Slitheen: Perfectly Imitated Decoy Routing through Traffic ReplacementCecylia Bocovich, Ian GoldbergCCS 2016 · 40 citations
