Stealthy Traffic Analysis of Low-Latency Anonymous Communication Using Throughput Fingerprinting
Prateek Mittal, Ahmed Khurshid, Joshua Juen, Matthew Caesar, Nikita, Borisov

TL;DR
This paper demonstrates that throughput fingerprinting can stealthily de-anonymize Tor users by identifying relays and linking connections, revealing significant privacy vulnerabilities in low-latency anonymous communication systems.
Contribution
The authors introduce novel throughput-based attacks that precisely identify relays and link user connections in Tor, surpassing previous methods in accuracy and stealth.
Findings
Median entropy of bottleneck relays reduced by a factor of 2
Exact identification of user guard relays over multiple connections
Linkage of two connections with less than 1.5% error in under 5 minutes
Abstract
Anonymity systems such as Tor aim to enable users to communicate in a manner that is untraceable by adversaries that control a small number of machines. To provide efficient service to users, these anonymity systems make full use of forwarding capacity when sending traffic between intermediate relays. In this paper, we show that doing this leaks information about the set of Tor relays in a circuit (path). We present attacks that, with high confidence and based solely on throughput information, can (a) reduce the attacker's uncertainty about the bottleneck relay of any Tor circuit whose throughput can be observed, (b) exactly identify the guard relay(s) of a Tor user when circuit throughput can be observed over multiple connections, and (c) identify whether two concurrent TCP connections belong to the same Tor user, breaking unlinkability. Our attacks are stealthy, and cannot be readily…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Network Security and Intrusion Detection · Cryptographic Implementations and Security
