WFGuard: an Effective Fuzzing-testing-based Traffic Morphing Defense against Website Fingerprinting
Zhen Ling, Gui Xiao, Lan Luo, Rong Wang, Xiangyu Xu, Guangchi Liu
Abstract
Website fingerprinting (WF) attack is a type of traffic analysis attack. It enables a local and passive eavesdropper situated between the Tor client and the Tor entry node to deduce which websites the client is visiting. Currently, deep learning (DL) based WF attacks have overcome a number of proposed WF defenses, demonstrating superior performance compared to traditional machine learning (ML) based WF attacks. To mitigate this threat, we present WFGuard, a fuzzing-testing-based traffic morphing WF defense technique. WFGuard employs fine-grained neuron information within WF classifiers to design a joint optimization function and then applies gradient ascent to maximize both neurons value and misclassification possibility in DL-based WF classifiers. During each traffic mutation cycle, we propose a gradient based dummy traffic injection pattern generation approach, continuously mutating the traffic until a pattern emerges that can successfully deceive the classifier. Finally, the pattern present in successful variant traces are extracted and applied as defense strategies to Tor traffic. Extensive evaluations reveal that WFGuard can effectively decrease the accuracy of DL-based WF classifiers (e.g., DF and Var-CNN) to a mere 4.43%, while only incurring an 11.04% bandwidth overhead. This highlights the potential efficacy of our approach in mitigating WF attacks.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get cb69140e-11ef-44a3-a796-49cf10547c2aCited by top-tier papers1
Ask how each one uses itRelated papers
- Towards an Efficient Defense against Deep Learning based Website FingerprintingZhen Ling, Gui Xiao, Wenjia Wu, Xiaodan Gu et al.INFOCOM 2022 · 17 citations
- DFD: Adversarial Learning-based Approach to Defend Against Website FingerprintingAhmed Abusnaina, Rhongho Jang, Aminollah Khormali, DaeHun Nyang et al.INFOCOM 2020 · 51 citations
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 632 citations
- SoK: A Critical Evaluation of Efficient Website Fingerprinting DefensesNate Mathews, James K. Holland, Se Eun Oh, Mohammad Saidur Rahman et al.S&P 2023
- Trace-agnostic and Adversarial Training-resilient Website Fingerprinting DefenseLitao Qiao, Bang Wu, Heng Li, Cuiying Gao et al.INFOCOM 2024 · 8 citations
