首页> 外文会议>IEEE Conference on Computer Communications >Novel and Practical SDN-based Traceback Technique for Malicious Traffic over Anonymous Networks
【24h】

Novel and Practical SDN-based Traceback Technique for Malicious Traffic over Anonymous Networks

机译:基于实用的SDN基于匿名网络的恶意交通的基于SDN的回溯技术

获取原文

摘要

Diverse anonymous communication systems are widely deployed as they can provide the online privacy protection and Internet anti-censorship service. However, these systems are severely abused and a large amount of anonymous traffic is malicious. To mitigate this issue, we propose a novel and practical traceback technique to confirm the communication relationship between the suspicious server and the user. We leverage the software-defined network (SDN) switch at a destination server side to intercept target traffic towards the server and alter the advertised TCP window sizes so as to stealthily vary the traffic rate at the server. By carefully varying the traffic rate, we can successfully modulate a secret signal into the traffic. The traffic carrying the signal passes through the anonymous communication system and reaches the SDN switch at the user side. Then we can detect the modulated signal from the traffic so as to confirm the communication relationship between the server and the user. To validate the feasibility and effectiveness of our technique, extensive real-world experiments are performed using three popular anonymous communication systems, i.e., SSH tunnel, OpenVPN tunnel, and Tor. The results demonstrate that the detection rates approach 100% for SSH and Open VPN and 95% for Tor while the false positive rates are significantly low, approaching 0% for these three systems.
机译:不同的匿名通信系统被广泛部署,因为它们可以提供在线隐私保护和互联网反审查服务。然而,这些系统严重滥用,大量的匿名交通是恶意的。为了缓解此问题,我们提出了一种新颖的和实际的回溯技术来确认可疑服务器和用户之间的沟通关系。我们利用目的地服务器端的软件定义的网络(SDN)交换机拦截到服务器的目标流量,并更改广告的TCP窗口大小,以便悄悄地改变服务器的流量速率。通过仔细改变流量率,我们可以成功调制秘密信号进入流量。承载信号的流量通过匿名通信系统,并在用户侧到达SDN开关。然后我们可以检测来自流量的调制信号,以便确认服务器和用户之间的通信关系。为验证我们技术的可行性和有效性,使用三个流行的匿名通信系统,即SSH隧道,OpenVPN隧道和TOR进行广泛的现实实验。结果表明,检测率接近SSH和Open VPN的100%,对于TOR为95%,而假阳性率明显低,这三个系统接近0%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号