• DocumentCode
    3436102
  • Title

    Background Knowledge-Resistant Traffic Padding for Preserving User Privacy in Web-Based Applications

  • Author

    Wen Ming Liu ; Lingyu Wang ; Kui Ren ; Debbabi, Mourad

  • Author_Institution
    Concordia Inst. for Inf. Syst. Eng., Concordia Univ., Montreal, QC, Canada
  • Volume
    1
  • fYear
    2013
  • fDate
    2-5 Dec. 2013
  • Firstpage
    679
  • Lastpage
    686
  • Abstract
    While enjoying the convenience of Software as a Service (SaaS), users are also at an increased risk of privacy breaches. Recent studies show that a Web-based application may be inherently vulnerable to side-channel attacks which exploit unique packet sizes to identify sensitive user inputs from encrypted traffic. Existing solutions based on packet padding or packet-size rounding generally rely on the assumption that adversaries do not possess prior background knowledge about possible user inputs. In this paper, we propose a novel random ceiling padding approach whose results are resistant to such adversarial knowledge. Specifically, the approach injects randomness into the process of forming padding groups, such that an adversary armed with background knowledge would still face sufficient uncertainty in estimating user inputs. We formally present a generic scheme and discuss two concrete instantiations. We then confirm the correctness and performance of our approach through both theoretic analysis and experiments with two real world applications.
  • Keywords
    cloud computing; data privacy; random processes; SaaS; Web-based application; background knowledge-resistant traffic padding; packet-size rounding; random ceiling padding; side-channel attack; software as a service; user privacy preservation; Cancer; Diseases; Measurement; Privacy; Servers; Transient analysis; Uncertainty; Background Knowledge; Indistinguishability; Privacy Preservation; Side-Channel Attack; Traffic Padding; Uncertainty; Web Application;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cloud Computing Technology and Science (CloudCom), 2013 IEEE 5th International Conference on
  • Conference_Location
    Bristol
  • Type

    conf

  • DOI
    10.1109/CloudCom.2013.96
  • Filename
    6753861