The Devils in The Details: Placing Decoy Routers in the Internet
Devashish Gosain, Anshika Agarwal, Sambuddho Chakravarty, H. B., Acharya

TL;DR
This paper explores the strategic placement of Decoy Routers within a small number of key Autonomous Systems to efficiently intercept internet traffic for anti-censorship, revealing both feasibility and significant cost challenges.
Contribution
It demonstrates that a small set of about 30 ASes can intercept most paths to popular websites, and details the precise placement of approximately 11,700 DRs within these ASes.
Findings
Approximately 30 ASes intercept over 90% of paths to top sites.
Around 11,700 DRs are needed for effective coverage.
Cost of deploying DRs exceeds 10 billion USD, making it a major challenge.
Abstract
Decoy Routing, the use of routers (rather than end hosts) as proxies, is a new direction in anti-censorship research. Decoy Routers (DRs), placed in Autonomous Systems, proxy traffic from users; so the adversary, e.g., a censorious government, attempts to avoid them. It is quite difficult to place DRs so the adversary cannot route around them for example, we need the cooperation of 850 ASes to contain China alone. In this paper, we consider a different approach. We begin by noting that DRs need not intercept all the network paths from a country, just those leading to Overt Destinations, i.e., unfiltered websites hosted outside the country (usually popular ones, so that client traffic to the OD does not make the censor suspicious. Our first question is; How many ASes are required for installing DRs to intercept a large fraction of paths from, e.g., China to the top n websites (as per…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Network Security and Intrusion Detection · Spam and Phishing Detection
