Defending against Traffic Analysis Attacks with Flexible In-Network Obfuscation
Guorui Xie, Qing Li, Zhenning Shi, Gianni Antichi, Yijia Zhu, Kejun Li, Changxing Weng, Sebastiano Miano, Yong Jiang, Mingwei Xu
摘要
Traffic analysis attacks can exploit side channels in encrypted traffic (e.g., packet sizes) to infer user activities. Existing defenses provide weak protection, impose excessive bandwidth overhead, or require hard-to-deploy coordination. We present Securitas, a novel network traffic obfuscation framework that protects from side-channel attacks using a learning-guided mix of packet fragmentation and insertion. We implemented Securitas on a number of different data planes: Tofino switch, AMD/Xilinx FPGA, eBPF, and BMv2. Experiments show that Securitas reduces attack accuracy by up to 95.89%, while consuming 42.69× less bandwidth than prior defenses. Realworld Internet tests confirm minimal performance impact, e.g., adding 0.15s to the web page load.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper8
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 被引用 632 次
- Automated Website Fingerprinting through Deep LearningVera Rimmer, Davy Preuveneers, Marc Juarez, Tom van Goethem 等NDSS 2018 · 被引用 399 次
- Defeating DNN-Based Traffic Analysis Systems in Real-Time With Blind Adversarial PerturbationsMilad Nasr, Alireza Bahramali, Amir HoumansadrUSENIX Security 2021 · 被引用 142 次
- High Precision Open-World Website FingerprintingTao WangS&P 2020 · 被引用 95 次
- Statistical Privacy for Streaming TrafficXiaokuan Zhang, Jihun Hamm, Michael K. Reiter, Yinqian ZhangNDSS 2019 · 被引用 49 次
相关 Paper
- ditto: WAN Traffic Obfuscation at Line RateRoland Meier, Vincent Lenders, Laurent VanbeverNDSS 2022
- Minos : A Lightweight and Dynamic Defense against Traffic Analysis in Programmable Data PlanesZihao Wang, Qing Li, Guorui Xie, Dan Zhao 等USENIX ATC 2025 · 被引用 4 次
- Wedjat: Detecting Sophisticated Evasion Attacks via Real-time Causal AnalysisLi Gao, Chuanpu Fu, Xinhao Deng, Ke Xu 等KDD 2025 · 被引用 2 次
- NetShaper: A Differentially Private Network Side-Channel Mitigation SystemAmir Sabzi, Rut Vora, Swati Goswami, Margo I. Seltzer 等USENIX Security 2024 · 被引用 7 次
- FaaSGuard: An Adaptive Framework for Obfuscating Function Activity States in Serverless ApplicationsXue Leng, Fengming Zhu, Xing Li, Tiantian Zhu 等INFOCOM 2026 · 被引用 1 次
