Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Tik-Tok: The Utility of Packet Timing in Website Fingerprinting Attacks

About

A passive local eavesdropper can leverage Website Fingerprinting (WF) to deanonymize the web browsing activity of Tor users. The value of timing information to WF has often been discounted in recent works due to the volatility of low-level timing information. In this paper, we more carefully examine the extent to which packet timing can be used to facilitate WF attacks. We first propose a new set of timing-related features based on burst-level characteristics to further identify more ways that timing patterns could be used by classifiers to identify sites. Then we evaluate the effectiveness of both raw timing and directional timing which is a combination of raw timing and direction in a deep-learning-based WF attack. Our closed-world evaluation shows that directional timing performs best in most of the settings we explored, achieving: (i) 98.4% in undefended Tor traffic; (ii) 93.5% on WTF-PAD traffic, several points higher than when only directional information is used; and (iii) 64.7% against onion sites, 12% higher than using only direction. Further evaluations in the open-world setting show small increases in both precision (+2%) and recall (+6%) with directional-timing on WTF-PAD traffic. To further investigate the value of timing information, we perform an information leakage analysis on our proposed handcrafted features. Our results show that while timing features leak less information than directional features, the information contained in each feature is mutually exclusive to one another and can thus improve the robustness of a classifier.

Mohammad Saidur Rahman, Payap Sirinam, Nate Mathews, Kantha Girish Gangadhara, Matthew Wright• 2019

Related benchmarks

TaskDatasetResultRank
Website FingerprintingMulti-tab Website Fingerprinting Closed-world 5-tab
P@541.34
20
Website FingerprintingMulti-tab Website Fingerprinting Open-world 4-tab
P@449.02
20
Website FingerprintingMulti-tab Website Fingerprinting Open-world 5-tab
P@542.74
20
Website FingerprintingMulti-tab Website Fingerprinting Closed-world 3-tab
Precision@353.51
20
Website FingerprintingMulti-tab Website Fingerprinting Open-world 2-tab
P@269.04
20
Binary Anomaly DetectionTor traffic dataset binary perturbation detection (test)
Accuracy75.96
12
Website FingerprintingMulti-tab Website Fingerprinting Closed-world 4-tab
Precision@449.6
10
Website FingerprintingTrafficSliver (2-tab)
AUC93.8
10
Website FingerprintingMulti-tab Website Fingerprinting Closed-world 2-tab
P@270.47
10
Website FingerprintingMulti-tab Website Fingerprinting Open-world 3-tab
P@353.35
10
Showing 10 of 24 rows

Other info

Code

Follow for update