Breaking Through the Diversity: Encrypted Video Identification Attack Based on QUIC Features
摘要
Video traffic is increasingly dominating the Internet, and most video platforms encrypt their transmissions to ensure content security and user privacy. However, attackers can still leverage traffic analysis methods to identify the being-watching videos, a practice known as the video identification attack. Nevertheless, traditional methods for encrypted video identification attacks have become ineffective as video platforms adopt the combined transmission mode and the QUIC transmission protocol. The combined transmission mode diversifies video traffic patterns, and the UDP-based QUIC protocol no longer provides the TCP header information commonly exploited in existing research. These changes in the transmission environment pose new challenges for video identification attacks. To address this, we propose a novel attack method to identify encrypted QUIC videos in combined transmission scenarios. We utilize a pre-established key-value structured real fingerprint database to match transmission fingerprints corrected with QUIC features. Additionally, we design a fingerprint-matching method, HBFMM, to efficiently implement video identification attacks. We evaluate our method with real video traffic from YouTube and validate the applicability on Facebook and Instagram, achieving closed-world accuracies of 99.04%, 98.11%, and 98.03%, with open-world accuracies exceeding 97%. Our work reveals exploitable vulnerabilities in the new transmission environment and proposes a possible countermeasure to better promote user privacy protection.