首页> 外文会议>Information security technology for applications. >Analyzing Characteristic Host Access Patterns for Re-identification of Web User Sessions
【24h】

Analyzing Characteristic Host Access Patterns for Re-identification of Web User Sessions

机译:分析特征主机访问模式以重新标识Web用户会话

获取原文
获取原文并翻译 | 示例

摘要

An attacker, who is able to observe a web user over a long period of time, learns a lot about his interests. It may be difficult to track users with regularly changing IP addresses, though. We show how patterns mined from web traffic can be used to re-identify a majority of users, i.e. link multiple sessions of them. We implement the web user re-identification attack using a Multinomial Naive Bayes classifier and evaluate it using a real-world dataset from 28 users. Our evaluation setup complies with the limited knowledge of an attacker on a malicious web proxy server, who is only able to observe the host names visited by its users. The results suggest that consecutive sessions can be linked with high probability for session durations from 5 minutes to 48 hours and that user profiles degrade only slowly over time. We also propose basic countermeasures and evaluate their efficacy.
机译:能够长期观察Web用户的攻击者可以从中学到很多有关他的兴趣的知识。但是,跟踪具有定期更改的IP地址的用户可能很困难。我们展示了如何从网络流量中挖掘出的模式可用于重新识别大多数用户,即链接他们的多个会话。我们使用多项朴素贝叶斯分类器实施网络用户重新识别攻击,并使用来自28个用户的真实数据集对其进行评估。我们的评估设置符合恶意Web代理服务器上攻击者的有限知识,该攻击者只能观察其用户访问的主机名。结果表明,连续的会话可以很可能链接到5分钟到48小时的会话持续时间,并且用户配置文件随着时间的推移只会缓慢降级。我们还提出了基本的对策,并评估了它们的功效。

著录项

  • 来源
  • 会议地点 Espoo(FI);Espoo(FI)
  • 作者单位

    Research Group Security in Distributed Systems Department of Informatics University of Hamburg, 22527 Hamburg, Germany;

    Research Group Security in Distributed Systems Department of Informatics University of Hamburg, 22527 Hamburg, Germany;

    Research Group Security in Distributed Systems Department of Informatics University of Hamburg, 22527 Hamburg, Germany;

    Research Group Security in Distributed Systems Department of Informatics University of Hamburg, 22527 Hamburg, Germany;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 安全保密;安全保密;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号