网络与信息安全学报 ›› 2019, Vol. 5 ›› Issue (4): 91-98.doi: 10.11959/j.issn.2096-109x.2019041

• 学术论文 • 上一篇    下一篇

基于改进IPD质心的Tor网络流水印检测方法

杜捷(),何永忠,杜晔   

  1. 北京交通大学计算机与信息技术学院,北京100044
  • 出版日期:2019-08-15 发布日期:2019-08-20
  • 作者简介:杜捷(1993- ),男,青海海东人,北京交通大学硕士生,主要研究方向为网络安全、匿名通信。|何永忠(1969- ),男,重庆人,博士,北京交通大学副教授、硕士生导师,主要研究方向为网络安全、计算机安全、密码协议。|杜晔(1978- ),男,黑龙江哈尔滨人,博士,北京交通大学副教授、博士生导师,主要研究方向为网络安全、态势感知、软件可靠性分析与评估。

Improved method of Tor network flow watermarks based on IPD interval

Jie DU(),Yongzhong HE,Ye DU   

  1. School of Computer and Information Technology,Beijing Jiaotong University,Beijing 100044,China
  • Online:2019-08-15 Published:2019-08-20

摘要:

Tor是一种为隐藏流量源提供服务的匿名网络机制,但其存在入口流量特征明显、易被识别的问题。obfs4等网桥协议为解决此问题应运而生,由此带来的新挑战尚未攻克,因此,提出一种IPD质心方案,利用k-means的聚类特性将原方案进行改进,使加入的流水印在obfs4网桥3种模式上均能被高效地检测出。实验结果表明,改进后的算法有更高的检测率和识别率,且应对不同的网络环境有较强的适应能力,有利于良好安全网络环境的构建。

关键词: 主动流量分析, 网络流水印, 匿名通信, Tor

Abstract:

Tor is an anonymous network mechanism that provides services for hiding traffic sources,but it has the problem that the entry traffic flows of Tor are clearly identifiable.Bridge protocols such as obfs4 come into being to solve this problem,which brings new challenges that have not yet been overcome.An IPD interval scheme is proposed,which uses the clustering characteristics of k-means to improve the original scheme,so that the added flow watermark can be detected efficiently in the three modes of obfs4 bridges.The results of experiments show that the improved algorithm has higher detection rate and recognition rate,and has good adaptability to variable netflow traffic,which is conducive to the construction of a nice secure network environment.

Key words: active traffic analysis, network flow watermarks, anonymous communication, Tor

中图分类号: 

No Suggested Reading articles found!