Efficient and Low Overhead Website Fingerprinting Attacks and Defenses based on TCP/IP Traffic
Guodong Huang, Chuan Ma, Ming Ding, Yuwen Qian, Chunpeng Ge, Liming Fang, Zhe Liu
摘要
Website fingerprinting attack is an extensively studied technique used in a web browser to analyze traffic patterns and thus infer confidential information about users. Several website fingerprinting attacks based on machine learning and deep learning tend to use the most typical features to achieve a satisfactory performance of attacking rate. However, these attacks suffer from several practical implementation factors, such as a skillfully pre-processing step or a clean dataset. To defend against such attacks, random packet defense (RPD) with a high cost of excessive network overhead is usually applied. In this work, we first propose a practical filter-assisted attack against RPD, which can filter out the injected noises using the statistical characteristics of TCP/IP traffic. Then, we propose a list-assisted defensive mechanism to defend the proposed attack method. To achieve a configurable trade-off between the defense and the network overhead, we further improve the list-based defense by a traffic splitting mechanism, which can combat the mentioned attacks as well as save a considerable amount of network overhead. In the experiments, we collect real-life traffic patterns using three mainstream browsers, i.e., Microsoft Edge, Google Chrome, and Mozilla Firefox, and extensive results conducted on the closed and open-world datasets show the effectiveness of the proposed algorithms in terms of defense accuracy and network efficiency.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- STAR: Semantic-Traffic Alignment and Retrieval for Zero-Shot HTTPS Website FingerprintingYifei Cheng, Yujia Zhu, Baiyang Li, Xinhao Deng 等INFOCOM 2026 · 被引用 4 次
- SoK: Decoding the Enigma of Encrypted Network Traffic ClassifiersNimesha Wickramasinghe, Arash Shaghaghi, Gene Tsudik, Sanjay K. JhaS&P 2025
它引用的顶会 Paper7
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 被引用 632 次
- Website Fingerprinting at Internet ScaleAndriy Panchenko, Fabian Lanze, Jan Pennekamp, Thomas Engel 等NDSS 2016 · 被引用 625 次
- Automated Website Fingerprinting through Deep LearningVera Rimmer, Davy Preuveneers, Marc Juarez, Tom van Goethem 等NDSS 2018 · 被引用 399 次
- Triplet Fingerprinting: More Practical and Portable Website Fingerprinting with N-shot LearningPayap Sirinam, Nate Mathews, Mohammad Saidur Rahman, Matthew WrightCCS 2019 · 被引用 268 次
- Walkie-Talkie: An Efficient Defense Against Passive Website Fingerprinting AttacksTao Wang, Ian GoldbergUSENIX Security 2017 · 被引用 249 次
相关 Paper
- DFD: Adversarial Learning-based Approach to Defend Against Website FingerprintingAhmed Abusnaina, Rhongho Jang, Aminollah Khormali, DaeHun Nyang 等INFOCOM 2020 · 被引用 51 次
- Zero-delay Lightweight Defenses against Website FingerprintingJiajun Gong, Tao WangUSENIX Security 2020
- WFGuard: an Effective Fuzzing-testing-based Traffic Morphing Defense against Website FingerprintingZhen Ling, Gui Xiao, Lan Luo, Rong Wang 等INFOCOM 2024 · 被引用 6 次
- Trace-agnostic and Adversarial Training-resilient Website Fingerprinting DefenseLitao Qiao, Bang Wu, Heng Li, Cuiying Gao 等INFOCOM 2024 · 被引用 8 次
- Towards an Efficient Defense against Deep Learning based Website FingerprintingZhen Ling, Gui Xiao, Wenjia Wu, Xiaodan Gu 等INFOCOM 2022 · 被引用 17 次
