Website Fingerprintjng
Claudia Diaz KU Leuven – COSIC
(With thanks to Marc Juarez and Bekah Overdorf)
Summer School on real-world crypto and privacy June 2017
W e b s i t e F i n g e r p r i n tj n g Claudia Diaz KU Leuven - - PowerPoint PPT Presentation
W e b s i t e F i n g e r p r i n tj n g Claudia Diaz KU Leuven COSIC (With thanks to Marc Juarez and Bekah Overdorf) Summer School on real-world crypto and privacy June 2017 Outline Website Fingerprintjng for htups sites Website
(With thanks to Marc Juarez and Bekah Overdorf)
Summer School on real-world crypto and privacy June 2017
htups
htups htups train test
current state and on its input
5
7
directory server directory server download public (onion) keys
Tor Web
Tor Web
Tor Web
Tor Web
Tor Web
Client Introduction Point (IP) Rendezvous Point (RP) HS-IP HS-RP xyz.onion HSDir Client-RP
HS-RP circuits are distinguishable from normal circuits (Kwon et al, 2015) Size of the HS world is estimated at a few thousands (closed world!)
instances that belong to the same site.
websites.
User Tor Web Adversary
Control Test (0.5s)
77.08% 9.8% 7.9% 8.23%
Test (3s) Test (5s)
Accuracy for difgerent tjme gaps
Time BW Tab 2 Tab 1
Control (3.5.2.1) Test (2.4.7) Test (3.5) 79.58% 66.75% 6.51%
User Tor Web Adversary
VM New York VM Leuven VM Singapore
12
KU Leuven DigitalOcean (virtual private servers)
VM New York VM Leuven VM Singapore
66.95% 8.83% Control (LVN) Test (NY)
12
VM New York VM Leuven VM Singapore
66.95% 9.33% Control (LVN) Test (SI)
12
VM New York VM Leuven VM Singapore
76.40% 68.53% Test (NY) Control (SI)
12
User Tor Web Adversary
Accuracy (%) Time (days)
Less than 50% afuer 9d.
18
19
20
21
22
23
Some sites are hidden from all methods! Some sites are hidden from all methods!
. . 2 5 . 5 . 7 5 . 1 . . 2 5 . 5 . 7 5 . 1
True Site − Median Predicted Site − Median
wild