While anonymity networks like Tor aim to protect the privacy of their users, they are vulnerable to traffic analysis attacks such as Website Fingerprinting (WF) and Flow Correlation (FC). Recent implementations of WF and FC attacks, such as Tik-Tok and DeepCoFFEA, have shown that the attacks can be effectively carried out, threatening user privacy. Consequently, there is a need for effective traffic analysis defense. There are a variety of existing defenses, but most are either ineffective, incur high latency and bandwidth overhead, or require additional infrastructure. As a result, we aim to design a traffic analysis defense that is efficient and highly resistant to both WF and FC attacks. We propose DeTorrent, which uses competing neural networks to generate and evaluate traffic analysis defenses that insert 'dummy' traffic into real traffic flows. DeTorrent operates with moderate overhead and without delaying traffic. In a closed-world WF setting, it reduces an attacker's accuracy by 60.5%, a reduction 9.5% better than the next-best padding-only defense. Against the state-of-the-art FC attacker, DeTorrent reduces the true positive rate for a $10^{-4}$ false positive rate to about .30, which is less than half that of the next-best defense. We also demonstrate DeTorrent's practicality by deploying it alongside the Tor network and find that it maintains its performance when applied to live traffic.
翻译:虽然Tor等匿名网络旨在保护用户隐私,但其易受网站指纹识别与流量关联等流量分析攻击。最新实现的WF与FC攻击(如Tik-Tok与DeepCoFFEA)已证明这些攻击可被有效实施,威胁用户隐私。因此,亟需有效的流量分析防御手段。现有多种防御方案,但多数存在效果不佳、延迟与带宽开销过高或需额外基础设施等缺陷。为此,我们致力于设计一种能高效抵御WF与FC攻击的流量分析防御方案。本文提出DeTorrent,通过竞争神经网络生成并评估向真实流量中插入“虚拟”流量的防御策略。DeTorrent在适度开销下运行且不延迟流量。在封闭世界WF场景中,其将攻击者准确率降低60.5%,降幅较次优的仅填充防御方案提升9.5%。针对最先进的FC攻击,DeTorrent在$10^{-4}$假阳性率条件下将真阳性率降至约0.30,不足次优防御方案的一半。我们还将DeTorrent部署于Tor网络以验证其实用性,发现其在处理实时流量时仍能保持原有性能。