|
ABSTRACT
Low latency anonymity systems are susceptive to traffic analysis attacks. In this paper, we propose a dependent link padding scheme to protect anonymity systems from traffic analysis attacks while providing a strict delay bound. The covering traffic generated by our scheme uses the minimum sending rate to provide full anonymity for a given set of flows. The relationship between user anonymity and the minimum covering traffic rate is then studied via analysis and simulation. When user flows are Poisson processes with the same sending rate, the minimum covering traffic rate to provide full anonymity to m users is O(log m). For Pareto traffic, we show that the rate of the covering traffic converges to a constant when the number of flows goes to infinity. Finally, we use real Internet trace files to study the behavior of our algorithm when user flows have different rates.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
 |
1
|
|
| |
2
|
G. Danezis, "The traffic analysis of continuous-time mixes," in Proceedings of Privacy Enhancing Technologies Workshop (PET), 2004.
|
 |
3
|
|
| |
4
|
U. Moeller, L. Cottrell, P. Palfrader, and L. Sassaman, "IETF draft: Mixmaster protocol version 2," http://www.ietf.org/internet-drafts/draft-sassaman-mixmaster-03.txt, 2004.
|
| |
5
|
M. Reed, P. Syverson, and D. Goldschlag, "Anonymous connections and onion routing," IEEE Journal on Selected Areas in Communications, vol. 16, no. 4, pp. 482--494, 1998.
|
| |
6
|
|
 |
7
|
|
| |
8
|
A. Serjantov and P. Sewell, "Passive Attack Analysis for Connection--Based Anonymity Systems," in Proceedings of European Symposium on Research in Computer Security, 2003.
|
| |
9
|
V. Anantharam and S. Verdu, "Bits through queues," IEEE Trans. on Information Theory, vol. 42, no. 1, pp. 4--18, 1996.
|
| |
10
|
|
| |
11
|
P. Venkitasubramaniam, T. He, and L. Tong, "Relay secrecy in wireless networks with eavesdroppers," in Proceedings of Allerton Conference on Communication, Control and Computing, 2006.
|
| |
12
|
Andreas Pfitzmann , Birgit Pfitzmann , Michael Waidner, ISDN-MIXes: Untraceable Communication with Small Bandwidth Overhead, Kommunikation in Verteilten Systemen, Grundlagen, Anwendungen, Betrieb, GI/ITG-Fachtagung, p.451-463, February 20-22, 1991
|
| |
13
|
|
| |
14
|
P. Boucher, A. Shostack, and I. Goldberg, "Freedom systems 2.0 architecture,"White paper, Zero Knowledge Systems, Inc., December 2000.
|
| |
15
|
S. J. Murdoch and P. Zielinski, "Sampled traffic analysis by internet-exchange-level adversaries," in Proceedings of Privacy Enhancing Technologies Workshop (PET), 2007.
|
| |
16
|
|
 |
17
|
|
| |
18
|
|
| |
19
|
V. Shmatikov and M. Wang, "Timing analysis in low-latency mix networks: attacks and defenses?" in Proceedings of ESORICS, 2006.
|
| |
20
|
A. Serjantov and G. Danezis, "Towards an information theoretic metric for anonymity," in Proceedings of Privacy Enhancing Technologies Workshop (PET), 2002.
|
| |
21
|
C. Diaz, S. Seys, J. Claessens, and B. Preneel, "Towards measuring anonymity," in Proceedings of Privacy Enhancing Technologies Workshop (PET), 2002.
|
| |
22
|
B. Bollobas, Modern Graph Theory. Springer, 1998.
|
| |
23
|
A. Blum, D. Song, and S. Venkataraman, "Detection of interactive stepping stones: Algorithms and confidence bounds," in Proceedings of International Symposium on Recent Advances In Intrusion Detection, 2004.
|
| |
24
|
T. He and L. Tong, "Detecting information flows: Improving chaff tolerance by joint detection," in Proceedings of Annual Conference Information Sciences and Systems (CISS), 2007.
|
 |
25
|
|
| |
26
|
|
| |
27
|
A. Papoulis and S. U. Pillai, Probability, Random Variables and Stochastic Processes. 4th Ed. McGraw Hill, 2002.
|
| |
28
|
P. Venkitasubramaniam, T. He, and L. Tong, "Anonymous networking amidst eavesdroppers," IEEE Transactions on Information Theory, vol. 54, no. 6, pp. 2770--2784, 2008.
|
| |
29
|
J. W. Cohen, The Single Server Queue. North-Holland, 1982.
|
| |
30
|
|
| |
31
|
N. L. for Applied Network Research., "Auckland-viii data set," http://pma.nlanr.net/Special/auck8.html, 2003.
|
|