SiamHAN: IPv6 Address Correlation Attacks on TLS Encrypted Traffic via Siamese Heterogeneous Graph Attention Network

04/20/2022
by   Tianyu Cui, et al.
0

Unlike IPv4 addresses, which are typically masked by a NAT, IPv6 addresses could easily be correlated with user activity, endangering their privacy. Mitigations to address this privacy concern have been deployed, making existing approaches for address-to-user correlation unreliable. This work demonstrates that an adversary could still correlate IPv6 addresses with users accurately, even with these protection mechanisms. To do this, we propose an IPv6 address correlation model - SiamHAN. The model uses a Siamese Heterogeneous Graph Attention Network to measure whether two IPv6 client addresses belong to the same user even if the user's traffic is protected by TLS encryption. Using a large real-world dataset, we show that, for the tasks of tracking target users and discovering unique users, the state-of-the-art techniques could achieve only 85 accuracy.

READ FULL TEXT
research
01/31/2021

Follow the Scent: Defeating IPv6 Prefix Rotation Privacy

IPv6's large address space provides ample freedom for assigning addresse...
research
04/19/2021

Multi-fold Correlation Attention Network for Predicting Traffic Speeds with Heterogeneous Frequency

Substantial efforts have been devoted to the investigation of spatiotemp...
research
06/19/2018

Self-adaptive Privacy Concern Detection for User-generated Content

To protect user privacy in data analysis, a state-of-the-art strategy is...
research
11/01/2019

Assessing the Privacy Benefits of Domain Name Encryption

As Internet users have become more savvy about the potential for their I...
research
06/24/2021

Context-aware Heterogeneous Graph Attention Network for User Behavior Prediction in Local Consumer Service Platform

As a new type of e-commerce platform developed in recent years, local co...
research
10/07/2021

Attacks on Onion Discovery and Remedies via Self-Authenticating Traditional Addresses

Onion addresses encode their own public key. They are thus self-authenti...
research
05/30/2022

Snoopy: A Webpage Fingerprinting Framework with Finite Query Model for Mass-Surveillance

Internet users are vulnerable to privacy attacks despite the use of encr...

Please sign up or login with your details

Forgot password? Click here to reset