In recent years, awareness of information security and the importance of protecting user privacy has grown significantly among Internet users. As a result, substantial effort is being invested to developing and deploying new protocols aimed at enhancing privacy and preventing the leakage of sensitive personal data. One of the most sensitive pieces of information at risk is the domain name, whose exposure can reveal a user’s browsing history and habits. To address this privacy concern, various technologies have been introduced, including DNS over TLS, DNS over HTTPS, DNS over QUIC, Encrypted Client Hello, and Protected QUIC Initial Packets. However, despite these advancements, studies have demonstrated that these mechanisms do not provide a fully comprehensive solution, as attackers can still infer users’ browsing activity under certain conditions. This is due to the fact that web pages are highly dynamic, with their content frequently changing. In this research, we propose an adaptive website fingerprinting attack based on a Siamese network model. We evaluate the effectiveness of the attack on both TLS and QUIC protocols and show that it can accurately infer domain names associated IP addresses using only a few traffic samples. Moreover, we demonstrate that the model maintains strong performance over time, enabling near real-time classification even several months after model training. The success of the attack and model’s robustness over time highlight the ongoing privacy risks faced by users, as our attack provides adversaries with a novel tool to uncover users’ browsing history and identify visited domain names.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Domain Name Encryption Does Not Ensure Privacy: Website Fingerprinting Attack With Only a Few Samples Using Siamese Network

  • Neriya Mazzuz,
  • Asaf Shabtai

摘要

In recent years, awareness of information security and the importance of protecting user privacy has grown significantly among Internet users. As a result, substantial effort is being invested to developing and deploying new protocols aimed at enhancing privacy and preventing the leakage of sensitive personal data. One of the most sensitive pieces of information at risk is the domain name, whose exposure can reveal a user’s browsing history and habits. To address this privacy concern, various technologies have been introduced, including DNS over TLS, DNS over HTTPS, DNS over QUIC, Encrypted Client Hello, and Protected QUIC Initial Packets. However, despite these advancements, studies have demonstrated that these mechanisms do not provide a fully comprehensive solution, as attackers can still infer users’ browsing activity under certain conditions. This is due to the fact that web pages are highly dynamic, with their content frequently changing. In this research, we propose an adaptive website fingerprinting attack based on a Siamese network model. We evaluate the effectiveness of the attack on both TLS and QUIC protocols and show that it can accurately infer domain names associated IP addresses using only a few traffic samples. Moreover, we demonstrate that the model maintains strong performance over time, enabling near real-time classification even several months after model training. The success of the attack and model’s robustness over time highlight the ongoing privacy risks faced by users, as our attack provides adversaries with a novel tool to uncover users’ browsing history and identify visited domain names.