首页> 外文会议>IEEE Conference on Computer Communications >Novel and Practical SDN-based Traceback Technique for Malicious Traffic over Anonymous Networks
【24h】

Novel and Practical SDN-based Traceback Technique for Malicious Traffic over Anonymous Networks

机译:基于SDN的新颖实用的匿名网络上恶意流量的回溯技术

获取原文

摘要

Diverse anonymous communication systems are widely deployed as they can provide the online privacy protection and Internet anti-censorship service. However, these systems are severely abused and a large amount of anonymous traffic is malicious. To mitigate this issue, we propose a novel and practical traceback technique to confirm the communication relationship between the suspicious server and the user. We leverage the software-defined network (SDN) switch at a destination server side to intercept target traffic towards the server and alter the advertised TCP window sizes so as to stealthily vary the traffic rate at the server. By carefully varying the traffic rate, we can successfully modulate a secret signal into the traffic. The traffic carrying the signal passes through the anonymous communication system and reaches the SDN switch at the user side. Then we can detect the modulated signal from the traffic so as to confirm the communication relationship between the server and the user. To validate the feasibility and effectiveness of our technique, extensive real-world experiments are performed using three popular anonymous communication systems, i.e., SSH tunnel, OpenVPN tunnel, and Tor. The results demonstrate that the detection rates approach 100% for SSH and Open VPN and 95% for Tor while the false positive rates are significantly low, approaching 0% for these three systems.
机译:各种各样的匿名通信系统可以提供在线隐私保护和Internet反审查服务,因此得到了广泛的部署。但是,这些系统被严重滥用,并且大量匿名通信是恶意的。为了缓解此问题,我们提出了一种新颖实用的回溯技术来确认可疑服务器与用户之间的通信关系。我们利用目标服务器端的软件定义网络(SDN)交换机来拦截向服务器的目标流量,并更改所通告的TCP窗口大小,从而秘密更改服务器的流量速率。通过仔细改变流量速率,我们可以成功地将秘密信号调制为流量。承载信号的流量通过匿名通信系统并到达用户端的SDN交换机。然后我们可以从流量中检测出调制信号,从而确定服务器与用户之间的通信关系。为了验证我们技术的可行性和有效性,我们使用三种流行的匿名通信系统(即SSH隧道,OpenVPN隧道和Tor)进行了广泛的实际实验。结果表明,SSH和Open VPN的检测率接近100%,Tor的检测率接近95%,而误报率非常低,这三个系统的接近率均为0%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号