Title
Sampled traffic analysis by internet-exchange-level adversaries
Abstract
Existing low-latency anonymity networks are vulnerable to traffic analysis, so location diversity of nodes is essential to defend against attacks. Previous work has shown that simply ensuring geographical diversity of nodes does not resist, and in some cases exacerbates, the risk of traffic analysis by ISPs. Ensuring high autonomous-system (AS) diversity can resist this weakness. However, ISPs commonly connect to many other ISPs in a single location, known as an Internet eXchange (IX). This paper shows that IXes are a single point where traffic analysis can be performed. We examine to what extent this is true, through a case study of Tor nodes in the UK. Also, some IXes sample packets flowing through them for performance analysis reasons, and this data could be exploited to de-anonymize traffic. We then develop and evaluate Bayesian traffic analysis techniques capable of processing this sampled data.
Year
DOI
Venue
2007
10.1007/978-3-540-75551-7_11
Privacy Enhancing Technologies
Keywords
Field
DocType
sampled traffic analysis,geographical diversity,ixes sample packet,location diversity,single point,tor node,internet exchange,traffic analysis,internet-exchange-level adversary,performance analysis reason,single location,bayesian traffic analysis technique,low latency
Traffic analysis,Internet exchange point,Computer science,Computer security,Network packet,Border Gateway Protocol,Autonomous system (mathematics),Anonymity,Traffic shaping,Hardware architecture
Conference
Volume
ISSN
ISBN
4776
0302-9743
3-540-75550-0
Citations 
PageRank 
References 
92
3.91
12
Authors
2
Name
Order
Citations
PageRank
Steven J. Murdoch180657.90
Piotr Zieliński21266.79