The Waterfall of Liberty: Decoy Routing Circumvention that Resists Routing Attacks
Milad Nasr, Hadi Zolfaghari, Amir Houmansadr
摘要
Decoy routing is an emerging approach for censorship circumvention in which circumvention is implemented with help from a number of volunteer Internet autonomous systems, called decoy ASes. Recent studies on decoy routing consider all decoy routing systems to be susceptible to a fundamental attack -regardless of their specific designs-in which the censors re-route traffic around decoy ASes, thereby preventing censored users from using such systems. In this paper, we propose a new architecture for decoy routing that, by design, is significantly stronger to rerouting attacks compared to all previous designs. Unlike previous designs, our new architecture operates decoy routers only on the downstream traffic of the censored users; therefore we call it downstream-only decoy routing. As we demonstrate through Internet-scale BGP simulations, downstream-only decoy routing offers significantly stronger resistance to rerouting attacks, which is intuitively because a (censoring) ISP has much less control on the downstream BGP routes of its traffic. Designing a downstream-only decoy routing system is a challenging engineering problem since decoy routers do not intercept the upstream traffic of censored users. We design the first downstreamonly decoy routing system, called Waterfall, by devising unique covert communication mechanisms. We also use various techniques to make our Waterfall implementation resistant to traffic analysis attacks. We believe that downstream-only decoy routing is a significant step towards making decoy routing systems practical. This is because a downstream-only decoy routing system can be deployed using a significantly smaller number of volunteer ASes, given a target resistance to rerouting attacks. For instance, we show that a Waterfall implementation with only a single decoy AS is as resistant to routing attacks (against China) as a traditional decoy system (e.g., Telex) with 53 decoy ASes.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Poking a Hole in the Wall: Efficient Censorship-Resistant Internet Communications by Parasitizing on WebRTCDiogo Barradas, Nuno Santos, Luís E. T. Rodrigues, Vítor NunesCCS 2020 · 被引用 41 次
- Conjure: Summoning Proxies from Unused Address SpaceSergey Frolov, Jack Wampler, Sze Chuen Tan, J. Alex Halderman 等CCS 2019 · 被引用 28 次
- Balboa: Bobbing and Weaving around Network CensorshipMarc B. Rosen, James Parker, Alex J. MalozemoffUSENIX Security 2021 · 被引用 22 次
- Enemy At the Gateways: Censorship-Resilient Proxy Distribution Using Game TheoryMilad Nasr, Sadegh Farhang, Amir Houmansadr, Jens GrossklagsNDSS 2019 · 被引用 15 次
- Bridging Barriers: A Survey of Challenges and Priorities in the Censorship Circumvention LandscapeDiwen Xue, Anna Ablove, Reethika Ramesh, Grace Kwak Danciu 等USENIX Security 2024 · 被引用 7 次
它引用的顶会 Paper4
- SoK: Towards Grounding Censorship Circumvention in EmpiricismMichael Carl Tschantz, Sadia Afroz, anonymous, Vern PaxsonS&P 2016 · 被引用 89 次
- Practical Censorship Evasion Leveraging Content Delivery NetworksHadi Zolfaghari, Amir HoumansadrCCS 2016 · 被引用 44 次
- Slitheen: Perfectly Imitated Decoy Routing through Traffic ReplacementCecylia Bocovich, Ian GoldbergCCS 2016 · 被引用 40 次
- GAME OF DECOYS: Optimal Decoy Routing Through Game TheoryMilad Nasr, Amir HoumansadrCCS 2016 · 被引用 25 次
相关 Paper
- Routing Around Congestion: Defeating DDoS Attacks and Adverse Network Conditions via Reactive BGP RoutingJared M. Smith, Max SchuchardS&P 2018 · 被引用 71 次
- On Precisely Detecting Censorship Circumvention in Real-World NetworksRyan Wails, George Arnold Sullivan, Micah Sherr, Rob JansenNDSS 2024
- On the Challenges of Geographical Avoidance for TorKatharina Kohls, Kai Jansen, David Rupprecht, Thorsten Holz 等NDSS 2019 · 被引用 22 次
- On the Feasibility of Rerouting-Based DDoS DefensesMuoi Tran, Min Suk Kang, Hsu-Chun Hsiao, Wei-Hsuan Chiang 等S&P 2019 · 被引用 39 次
- Avoiding The Man on the Wire: Improving Tor's Security with Trust-Aware Path SelectionAaron Johnson, Rob Jansen, Aaron D. Jaggard, Joan Feigenbaum 等NDSS 2017 · 被引用 30 次
