Proceedings Article10.1145/2810103.2813715
Seeing through Network-Protocol Obfuscation
Liang Wang,Kevin P. Dyer,Aditya Akella,Thomas Ristenpart,Thomas Shrimpton +4 more
- 12 Oct 2015
- pp 57-69
TL;DR: This work provides the first in-depth investigation of the detectability of in-use protocol obfuscators by DPI, and builds a framework for evaluation that uses real network traffic captures to evaluate detectability, based on metrics such as the false-positive rate against background traffic.
read more
Abstract: Censorship-circumvention systems are designed to help users bypass Internet censorship. As more sophisticated deep-packet-inspection (DPI) mechanisms have been deployed by censors to detect circumvention tools, activists and researchers have responded by developing network protocol obfuscation tools. These have proved to be effective in practice against existing DPI and are now distributed with systems such as Tor. In this work, we provide the first in-depth investigation of the detectability of in-use protocol obfuscators by DPI. We build a framework for evaluation that uses real network traffic captures to evaluate detectability, based on metrics such as the false-positive rate against background (i.e., non obfuscated) traffic. We first exercise our framework to show that some previously proposed attacks from the literature are not as effective as a censor might like. We go on to develop new attacks against five obfuscation tools as they are configured in Tor, including: two variants of obfsproxy, FTE, and two variants of meek. We conclude by using our framework to show that all of these obfuscation mechanisms could be reliably detected by a determined censor with sufficiently low false-positive rates for use in many censorship settings.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Identifying Encrypted Malware Traffic with Contextual Flow Data
Blake Anderson,David McGrew +1 more
- 28 Oct 2016
TL;DR: This work develops supervised machine learning models that take advantage of a unique and diverse set of network flow data features and shows that incorporating this contextual information into a supervised learning system significantly increases performance at a 0.00% false discovery rate for the problem of classifying encrypted, malicious flows.
254
Deciphering malware’s use of TLS (without decryption)
TL;DR: It is concluded that malware’s usage of TLS is distinct in an enterprise setting, and that these differences can be effectively used in rules and machine learning classifiers.
A review on machine learning–based approaches for Internet traffic classification
TL;DR: A comprehensive review of various data representation methods, and the different objectives of Internet traffic classification and obfuscation techniques, largely considering the ML-based solutions.
106
Turboflow: information rich flow record generation on commodity switches
John Sonchack,Adam J. Aviv,Eric Keller,Jonathan M. Smith +3 more
- 23 Apr 2018
TL;DR: The design, implementation, and evaluation of TurboFlow are presented, a flow record generator for programmable switches that does not compromise on either cost or information richness and can support multi-terabit workloads on readily available commodity switches to enable information rich monitoring with high coverage.
103
The use of TLS in Censorship Circumvention.
Sergey Frolov,Eric Wustrow +1 more
- 01 Jan 2019
TL;DR: Real-world TLS traffic from over 11.8 billion TLS connections over 9 months is collected to identify a wide range of TLS client implementations actually used on the Internet and develops a library, uTLS, that enables tool maintainers to automatically mimic other popular TLS implementations.
82
References
A Statistical Test Suite for Random and Pseudorandom Number Generators for Cryptographic Applications
Andrew L. Rukhin,Juan Soto,James R. Nechvatal,Miles E. Smid,Elaine B. Barker +4 more
- 20 Dec 2000
TL;DR: Some criteria for characterizing and selecting appropriate generators and some recommended statistical tests are provided, as a first step in determining whether or not a generator is suitable for a particular cryptographic application.
Bro: a system for detecting network intruders in real-time
Vern Paxson,Vern Paxson +1 more
TL;DR: An overview of the Bro system's design, which emphasizes high-speed (FDDI-rate) monitoring, real-time notification, clear separation between mechanism and policy, and extensibility, is given.
2.7K
Hive: a warehousing solution over a map-reduce framework
Ashish Thusoo,Joydeep Sen Sarma,Namit Jain,Zheng Shao,Prasad Chakka,Suresh Anthony,Hao Liu,Pete Wyckoff,Raghotham Murthy +8 more
- 01 Aug 2009
TL;DR: Hadoop is a popular open-source map-reduce implementation which is being used as an alternative to store and process extremely large data sets on commodity hardware.
BLINC: multilevel traffic classification in the dark
Thomas Karagiannis,Konstantina Papagiannaki,Michalis Faloutsos +2 more
- 22 Aug 2005
TL;DR: This work presents a fundamentally different approach to classifying traffic flows according to the applications that generate them, based on observing and identifying patterns of host behavior at the transport layer and demonstrates the effectiveness of this approach on three real traces.
A preliminary performance comparison of five machine learning algorithms for practical IP traffic flow classification
Nigel Williams,Sebastian Zander,Grenville Armitage +2 more
- 10 Oct 2006
TL;DR: The performance impact of feature set reduction, using Consistency-based and Correlation-based feature selection, is demonstrated on Na naïve Bayes, C4.5, Bayesian Network and Naïve Bayes Tree algorithms.