Show simple item record

dc.contributor.authorAbraham, Titusen_US
dc.date.accessioned2010-07-19T19:55:03Z
dc.date.available2010-07-19T19:55:03Z
dc.date.issued2010-07-19
dc.date.submittedJanuary 2010en_US
dc.identifier.otherDISS-10685en_US
dc.identifier.urihttp://hdl.handle.net/10106/4949
dc.description.abstractA mix is a communication proxy that hides the relationship between incoming and outgoing messages. Routing traffic through a path of mixes is a powerful tool for providing privacy. When mixes are used for interactive communication, such as VoIP and web browsing, attackers can undermine user privacy by observing timing information along the path. Mixes can prevent these attacks by inserting dummy packets (cover traffic) to obfuscate timing information in each stream. Two recently proposed defenses, defensive dropping and adaptive padding, enhance cover traffic by ensuring that timing information seen at the sender is very different from that seen at the receiver.In this work, we propose Selective Cross Correlation (SCC), an attack that an eavesdropper could employ to de-anonymize users despite the use of defensive dropping or adaptive padding. The main insight of our approach is that, with either defense, the timings at one end of the stream are a subset of the timings at the other end of the stream. By considering the network conditions and the defensive mechanism used, SCC can be used to effectively remove the cover traffic, thereby enabling the attacker to correlate both ends of the stream. We conducted real network experiments and found that SCC greatly improves attacker effectiveness over prior techniques against both the defenses. With SCC, the attacker is nearly as successful as when neither defense is applied. This attack demonstrates the need for more robust defenses against statistical timing attacks.en_US
dc.description.sponsorshipWright, Matthewen_US
dc.language.isoENen_US
dc.publisherComputer Science & Engineeringen_US
dc.titleSelective Cross Correlation In Passive Timing Analysis Attacks Against Low-latency Mixesen_US
dc.typeM.S.en_US
dc.contributor.committeeChairWright, Matthewen_US
dc.degree.departmentComputer Science & Engineeringen_US
dc.degree.disciplineComputer Science & Engineeringen_US
dc.degree.grantorUniversity of Texas at Arlingtonen_US
dc.degree.levelmastersen_US
dc.degree.nameM.S.en_US
dc.identifier.externalLinkhttps://www.uta.edu/ra/real/editprofile.php?onlyview=1&pid=215
dc.identifier.externalLinkDescriptionLink to Research Profiles


Files in this item

Thumbnail


This item appears in the following Collection(s)

Show simple item record