Results 1 to 1 of 1
-
25th Jun 2014, 11:17 AM #1
Patterns in Encrypted Web Traffic Can Disclose Sensitive Details
By analyzing patterns in encrypted web traffic, researchers found that they can identify access to specific pages on a website with an accuracy of 89%, even if their resources are being shared.
The research is at the beginning and has been documented in a paper called “I Know Why You Went to the Clinic: Risks and Realization of HTTPS Traffic Analysis,” to be presented in July, at the Privacy Enhancing Technologies Symposiun, in Amsterdam.
It is based on attacks carried out on more than 6,000 web pages spanning the HTTPS deployments of 10 widely-used websites in areas ranging from healthcare and finance to video streaming.
According to the paper, observing patterns in encrypted traffic could give an attacker insight into the personal details of the victims, such as medical conditions and their type, and even the sexual orientation by determining their video rental history.
In order to do that, the attacker needs to know the pages visited by the victim, so that the patterns in the encrypted traffic can be observed, and to be able to monitor the traffic in order to match it with previously learned patterns.
The attack model proposed consists in crawling the website to gather URLs and then analyze them “to produce a canonicalization function which, given a URL, returns a canonical label for the webpage loaded as a result of entering the URL into a browser address bar.” The canonicalization function is then used to create a graph of the website.
Among the adversaries that meet the two requirements are ISPs (Internet Service Providers), employers that can monitor all activity on the network and spying agencies.
Multiple defense techniques are also proposed, the Burst approach being the most effective because it modifies the packet size and makes pattern recognition more difficult.
“Burst defense which operates between the application and TCP layers to obscure high level features of traffic while minimizing overhead,” the researchers wrote.
The researchers say that their evaluation techniques bring an improved accuracy, of 89%, from the 60% recorded with other methods.
The websites included in the research are the Mayo Clinic, Planned Parenthood, Kaiser Permanente, Wells Fargo, Bank of America, Vanguard, the ACLU, Legal Zoom, Netflix and YouTube.
Interpretation of the results focuses on caching and user-specific cookies and does not explore factors such as browser differences, operating system differences or mobile devices used by the victim, which would lead to a lower accuracy.Kepler Reviewed by Kepler on . Patterns in Encrypted Web Traffic Can Disclose Sensitive Details http://i1-news.softpedia-static.com/images/news-700/Patterns-In-Encrypted-Web-Traffic-Can-Disclose-Sensitive-Details.jpg By analyzing patterns in encrypted web traffic, researchers found that they can identify access to specific pages on a website with an accuracy of 89%, even if their resources are being shared. The research is at the beginning and has been documented in a paper called “I Know Why You Went to the Clinic: Risks and Realization of HTTPS Traffic Analysis,” to be Rating: 5
Sponsored Links
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Similar Threads
-
Investing in a web hosting company - domain provided - servers provided
By brainst0rm in forum Completed TransactionsReplies: 0Last Post: 24th Sep 2010, 06:58 PM -
No. 1 Nation in Sexy Web Searches? Call it Pornistan
By MUS in forum General DiscussionReplies: 5Last Post: 17th Jul 2010, 02:41 AM -
I need help in encrypt download links for my site
By monsterfish in forum Webmaster DiscussionReplies: 2Last Post: 3rd Jul 2010, 04:34 AM -
How much traffic can 50GB bandwidth handle?
By bxflow in forum Hosting DiscussionReplies: 13Last Post: 20th Mar 2010, 07:01 PM -
Please help me in choosing web hosting
By 0xyGen in forum Hosting DiscussionReplies: 4Last Post: 12th Jul 2008, 03:04 PM
themaCreator - create posts from...
Version 3.24 released. Open older version (or...