This is not the padding you are looking for! On the ineffectiveness of QUIC PADDING against website fingerprinting

03/15/2022
by   Ludovic Barman, et al.
0

Website fingerprinting (WF) is a well-know threat to users' web privacy. New internet standards, such as QUIC, include padding to support defenses against WF. We study whether network-layer padding can indeed be used to construct effective WF defenses. We confirm previous claims that network-layer padding cannot provide good protection against powerful adversaries capable of observing all traffic traces. In contrast to prior work, we also demonstrate that such padding is ineffective even against adversaries with partial view of the traffic. Network-layer padding without application input is ineffective because it fails to hide information unique across different applications. We show that application-layer padding solutions need to be deployed by both first and third parties, and that they can only thwart traffic analysis in limited situations. We identify challenges to deploy effective WF defenses and provide recommendations to reduce these hurdles.

READ FULL TEXT

page 3

page 5

page 9

research
04/19/2023

Maybenot: A Framework for Traffic Analysis Defenses

End-to-end encryption is a powerful tool for protecting the privacy of I...
research
03/05/2021

PCP: Preemptive Circuit Padding against Tor circuit fingerprinting

Online anonymity and privacy has been based on confusing the adversary b...
research
04/20/2020

Securing Internet Applications from Routing Attacks

Attacks on Internet routing are typically viewed through the lens of ava...
research
06/24/2019

Encrypted DNS --> Privacy? A Traffic Analysis Perspective

Virtually every connection to an Internet service is preceded by a DNS l...
research
11/24/2021

WFDefProxy: Modularly Implementing and Empirically Evaluating Website Fingerprinting Defenses

Tor, an onion-routing anonymity network, has been shown to be vulnerable...
research
03/15/2022

SoK: Why Have Defenses against Social Engineering Attacks Achieved Limited Success?

Social engineering attacks are a major cyber threat because they often s...
research
11/26/2020

Towards Effective and Efficient Padding Machines for Tor

Tor recently integrated a circuit padding framework for creating padding...

Please sign up or login with your details

Forgot password? Click here to reset