DocumentCode
3092386
Title
Breaking Tor Anonymity with Game Theory and Data Mining
Author
Wagner, Cynthia ; Wagener, Gerard ; State, Radu ; Engel, Thomas ; Dulaunoy, Alexandre
Author_Institution
SECAN-Lab., Univ. of Luxembourg, Luxembourg, Luxembourg
fYear
2010
fDate
1-3 Sept. 2010
Firstpage
47
Lastpage
54
Abstract
Attacking anonymous communication networks is very tempting and many attacks have already been observed. We consider the case of Tor, a widely-used anonymous overlay network. Despite the deployment of several protection mechanisms, we propose an attack originated from only one rogue exit node. Our attack is composed of two elements. The first is an active tag injection scheme. The malicious exit node injects image tags into all HTTP replies, which will be cached for upcoming requests and allows different users to be distinguished. The second element is an inference attack that leverages a semi-supervised learning algorithm to reconstruct browsing sessions. Captured traffic flows are clustered into sessions, such that one session is most probably associated to a specific user. The clustering algorithm uses HTTP headers and logical dependencies encountered in a browsing session. We have implemented a prototype and evaluated its performance on the Tor network. The article also describes several counter-measures and advanced attacks, modeled in a game-theoretical framework and their relevancy assessed with reference to the Nash equilibrium.
Keywords
data mining; game theory; pattern clustering; security of data; Nash equilibrium; Tor Anonymity; anonymous communication networks; clustering algorithm; data mining; game theory; malicious exit node; semi-supervised learning algorithm; Browsers; Clustering algorithms; Data mining; Games; History; Servers; Tagging; Anonymity; Data Mining; Nash Equilibrium; Tor Session;
fLanguage
English
Publisher
ieee
Conference_Titel
Network and System Security (NSS), 2010 4th International Conference on
Conference_Location
Melbourne, VIC
Print_ISBN
978-1-4244-8484-3
Electronic_ISBN
978-0-7695-4159-4
Type
conf
DOI
10.1109/NSS.2010.54
Filename
5636086
Link To Document