Improved method of Tor network flow watermarks based on IPD interval

Tor is an anonymous network mechanism that provides services for hiding traffic sources, but it has the problem that the entry traffic flows of Tor are clearly identifiable. Bridge protocols such as obfs4 come into being to solve this problem, which brings new challenges that have not yet been overc...

Full description

Bibliographic Details
Main Author: DU Jie, HE Yongzhong, DU Ye
Format: Article
Language:English
Published: POSTS&TELECOM PRESS Co., LTD 2019-08-01
Series:网络与信息安全学报
Subjects:
Online Access:http://www.infocomm-journal.com/cjnis/CN/10.11959/j.issn.2096-109x.2019041
Description
Summary:Tor is an anonymous network mechanism that provides services for hiding traffic sources, but it has the problem that the entry traffic flows of Tor are clearly identifiable. Bridge protocols such as obfs4 come into being to solve this problem, which brings new challenges that have not yet been overcome. An IPD interval scheme is proposed, which uses the clustering characteristics of k-means to improve the original scheme, so that the added flow watermark can be detected efficiently in the three modes of obfs4 bridges. The results of experiments show that the improved algorithm has higher detection rate and recognition rate, and has good adaptability to variable netflow traffic, which is conducive to the construction of a nice secure network environment.
ISSN:2096-109X