Improved method of Tor network flow watermarks based on IPD interval

Tor is an anonymous network mechanism that provides services for hiding traffic sources, but it has the problem that the entry traffic flows of Tor are clearly identifiable. Bridge protocols such as obfs4 come into being to solve this problem, which brings new challenges that have not yet been overc...

Full description

Bibliographic Details
Main Author: DU Jie, HE Yongzhong, DU Ye
Format: Article
Language:English
Published: POSTS&TELECOM PRESS Co., LTD 2019-08-01
Series:网络与信息安全学报
Subjects:
Online Access:http://www.infocomm-journal.com/cjnis/CN/10.11959/j.issn.2096-109x.2019041
_version_ 1811290088329445376
author DU Jie, HE Yongzhong, DU Ye
author_facet DU Jie, HE Yongzhong, DU Ye
author_sort DU Jie, HE Yongzhong, DU Ye
collection DOAJ
description Tor is an anonymous network mechanism that provides services for hiding traffic sources, but it has the problem that the entry traffic flows of Tor are clearly identifiable. Bridge protocols such as obfs4 come into being to solve this problem, which brings new challenges that have not yet been overcome. An IPD interval scheme is proposed, which uses the clustering characteristics of k-means to improve the original scheme, so that the added flow watermark can be detected efficiently in the three modes of obfs4 bridges. The results of experiments show that the improved algorithm has higher detection rate and recognition rate, and has good adaptability to variable netflow traffic, which is conducive to the construction of a nice secure network environment.
first_indexed 2024-04-13T04:06:39Z
format Article
id doaj.art-794ffe01b0d64b629a76063e04e4cfe5
institution Directory Open Access Journal
issn 2096-109X
language English
last_indexed 2024-04-13T04:06:39Z
publishDate 2019-08-01
publisher POSTS&TELECOM PRESS Co., LTD
record_format Article
series 网络与信息安全学报
spelling doaj.art-794ffe01b0d64b629a76063e04e4cfe52022-12-22T03:03:14ZengPOSTS&TELECOM PRESS Co., LTD网络与信息安全学报2096-109X2019-08-0154919810.11959/j.issn.2096-109x.2019041Improved method of Tor network flow watermarks based on IPD intervalDU Jie, HE Yongzhong, DU Ye0School of Computer and Information Technology, Beijing Jiaotong University, Beijing 100044, ChinaTor is an anonymous network mechanism that provides services for hiding traffic sources, but it has the problem that the entry traffic flows of Tor are clearly identifiable. Bridge protocols such as obfs4 come into being to solve this problem, which brings new challenges that have not yet been overcome. An IPD interval scheme is proposed, which uses the clustering characteristics of k-means to improve the original scheme, so that the added flow watermark can be detected efficiently in the three modes of obfs4 bridges. The results of experiments show that the improved algorithm has higher detection rate and recognition rate, and has good adaptability to variable netflow traffic, which is conducive to the construction of a nice secure network environment.http://www.infocomm-journal.com/cjnis/CN/10.11959/j.issn.2096-109x.2019041active traffic analysisnetwork flow watermarksanonymous communicationtor
spellingShingle DU Jie, HE Yongzhong, DU Ye
Improved method of Tor network flow watermarks based on IPD interval
网络与信息安全学报
active traffic analysis
network flow watermarks
anonymous communication
tor
title Improved method of Tor network flow watermarks based on IPD interval
title_full Improved method of Tor network flow watermarks based on IPD interval
title_fullStr Improved method of Tor network flow watermarks based on IPD interval
title_full_unstemmed Improved method of Tor network flow watermarks based on IPD interval
title_short Improved method of Tor network flow watermarks based on IPD interval
title_sort improved method of tor network flow watermarks based on ipd interval
topic active traffic analysis
network flow watermarks
anonymous communication
tor
url http://www.infocomm-journal.com/cjnis/CN/10.11959/j.issn.2096-109x.2019041
work_keys_str_mv AT dujieheyongzhongduye improvedmethodoftornetworkflowwatermarksbasedonipdinterval