English
Related papers

Related papers: Padding-only defenses add delay in Tor

200 papers

In webpage fingerprinting, an on-path adversary infers the specific webpage loaded by a victim user by analysing the patterns in the encrypted TLS traffic exchanged between the user's browser and the website's servers. This work studies…

Cryptography and Security · Computer Science 2023-10-30 Vasilios Mavroudis , Jamie Hayes

Parallel to our physical activities our virtual presence also leaves behind our unique digital fingerprints, while navigating on the Internet. These digital fingerprints have the potential to unveil users' activities encompassing browsing…

Cryptography and Security · Computer Science 2024-09-09 Blerim Rexha , Arbena Musa , Kamer Vishi , Edlira Martiri

Website fingerprinting (WF) attacks on Tor can infer user destinations from encrypted traffic metadata. However, their real-world effectiveness remains debated due to laboratory settings that fail to capture network fluctuations, evaluate…

Cryptography and Security · Computer Science 2026-03-10 Mohammadhamed Shadbeh , Khashayar Khajavi , Tao Wang

The Tor anonymity network has been shown vulnerable to traffic analysis attacks by autonomous systems and Internet exchanges, which can observe different overlay hops belonging to the same circuit. We aim to determine whether network path…

Cryptography and Security · Computer Science 2015-03-05 Joshua Juen , Aaron Johnson , Anupam Das , Nikita Borisov , Matthew Caesar

Anonymity systems such as Tor aim to enable users to communicate in a manner that is untraceable by adversaries that control a small number of machines. To provide efficient service to users, these anonymity systems make full use of…

Cryptography and Security · Computer Science 2015-03-19 Prateek Mittal , Ahmed Khurshid , Joshua Juen , Matthew Caesar , Nikita Borisov

We introduce an attack against encrypted web traffic that makes use only of packet timing information on the uplink. This attack is therefore impervious to existing packet padding defences. In addition, unlike existing approaches this…

Networking and Internet Architecture · Computer Science 2016-07-12 Saman Feghhi , Douglas J. Leith

It is well known that when IoT traffic is unencrypted it is possible to identify the active devices based on their TCP/IP headers. And when traffic is encrypted, packet-sizes and timings can still be used to do so. To defend against such…

Cryptography and Security · Computer Science 2021-10-22 Aviv Engelberg , Avishai Wool

Darknet technology such as Tor has been used by various threat actors for organising illegal activities and data exfiltration. As such, there is a case for organisations to block such traffic, or to try and identify when it is used and for…

Cryptography and Security · Computer Science 2018-08-06 Hamish Haughey , Gregory Epiphaniou , Haider Al-Khateeb , Ali Dehghantanha

A passive local eavesdropper can leverage Website Fingerprinting (WF) to deanonymize the web browsing activity of Tor users. The value of timing information to WF has often been discounted in recent works due to the volatility of low-level…

Cryptography and Security · Computer Science 2020-10-12 Mohammad Saidur Rahman , Payap Sirinam , Nate Mathews , Kantha Girish Gangadhara , Matthew Wright

Website Fingerprinting (WF) aims to deanonymize users on the Tor network by analyzing encrypted network traffic. Recent deep-learning-based attacks show high accuracy on undefended traces. However, they struggle against modern defenses that…

Cryptography and Security · Computer Science 2024-12-17 Jiajun Gong , Wei Cai , Siyuan Liang , Zhong Guan , Tao Wang , Ee-Chien Chang

An attacker can gain information of a user by analyzing its network traffic. The size of transferred data leaks information about the file being transferred or the service being used, and this is particularly revealing when the attacker has…

Cryptography and Security · Computer Science 2022-09-12 Sebastian Simon , Cezara Petrui , Carlos Pinzón , Catuscia Palamidessi

Website Fingerprinting (WF) attacks exploit patterns in encrypted traffic to infer the websites visited by users, posing a serious threat to anonymous communication systems. Although recent WF techniques achieve over 90% accuracy in…

Cryptography and Security · Computer Science 2025-10-17 Xinhao Deng , Jingyou Chen , Linxiao Yu , Yixiang Zhang , Zhongyi Gu , Changhao Qiu , Xiyuan Zhao , Ke Xu , Qi Li

We measure how effective Privacy Enhancing Technologies (PETs) are at protecting users from website fingerprinting. Our measurements use both experimental and observational methods. Experimental methods allow control, precision, and use on…

Cryptography and Security · Computer Science 2018-12-11 Amit Datta , Jianan Lu , Michael Carl Tschantz

Attacks on Internet routing are typically viewed through the lens of availability and confidentiality, assuming an adversary that either discards traffic or performs eavesdropping. Yet, a strategic adversary can use routing attacks to…

Networking and Internet Architecture · Computer Science 2020-08-13 Yixin Sun , Maria Apostolaki , Henry Birge-Lee , Laurent Vanbever , Jennifer Rexford , Mung Chiang , Prateek Mittal

Browser fingerprinting is a growing technique for identifying and tracking users online without traditional methods like cookies. This paper gives an overview by examining the various fingerprinting techniques and analyzes the entropy and…

Cryptography and Security · Computer Science 2024-11-20 Alexander Lawall

The network flow watermarking technique associates the two communicating parties by actively modifying certain characteristics of the stream generated by the sender so that it covertly carries some special marking information. Some curious…

Networking and Internet Architecture · Computer Science 2024-02-08 Yali Yuan , Jian Ge , Guang Cheng

Tor is currently one of the more popular systems for anonymizing near real-time communications on the Internet. Recently, Borisov et al. proposed a denial of service based attack on Tor (and related systems) that significantly increases the…

Cryptography and Security · Computer Science 2013-10-04 Norman Danner , Sam DeFabbia-Kane , Danny Krizanc , Marc Liberatore

The use of anonymity-based infrastructures and anonymisers is a plausible solution to mitigate privacy problems on the Internet. Tor (short for The onion router) is a popular low-latency anonymity system that can be installed as an end-user…

Cryptography and Security · Computer Science 2012-08-21 Sergio Castillo-Perez , Joaquin Garcia-Alfaro

In this work we show that Tor is vulnerable to app deanonymization attacks on Android devices through network traffic analysis. For this purpose, we describe a general methodology for performing an attack that allows to deanonymize the apps…

Cryptography and Security · Computer Science 2019-01-15 Emanuele Petagna , Giuseppe Laurenza , Claudio Ciccotelli , Leonardo Querzoni

Recent studies have shown that Tor onion (hidden) service websites are particularly vulnerable to website fingerprinting attacks due to their limited number and sensitive nature. In this work we present a multi-level feature analysis of…

Cryptography and Security · Computer Science 2017-09-22 Rebekah Overdorf , Marc Juarez , Gunes Acar , Rachel Greenstadt , Claudia Diaz