Title
Obfuscating Encrypted Web Traffic with Combined Objects
Abstract
Web traffic demonstrates a sequence of request-response transactions during web page visiting. On one hand, the browser retrieves the basic HTML file and then issues requests in sequence for objects in HTML document. On the other hand, the server returns related objects in sequence as responses. This makes the traffic of a web page demonstrate pattern features different from other pages. Traffic analysis techniques can extract these features and identify web pages effectively even if the traffic is encrypted. In this paper, we propose a countermeasure method, CoOBJ, to defend against traffic analysis by obfuscating web traffic with combined objects. We compose some objects into a single object, the combined object, and force the object requests and responses on combined objects. By randomly composing objects with different objects, the traffic for a given web page is variable and exhibits different traffic patterns in different visits. We have implemented a proof of concept prototype and validate the CoOBJ countermeasure with some state of the art traffic analysis techniques.
Year
DOI
Venue
2014
10.1007/978-3-319-06320-1_8
ISPEC
Keywords
Field
DocType
combined object,encrypted web traffic,traffic analysis,web page identification
Static web page,Same-origin policy,Web traffic,Traffic analysis,Web page,Computer science,Web analytics,Computer security,Page view,Web service,Database
Conference
Citations 
PageRank 
References 
1
0.36
14
Authors
3
Name
Order
Citations
PageRank
Yi Tang120.72
Piaoping Lin220.72
Zhaokai Luo320.72