...
首页> 外文期刊>IEEE transactions on wireless communications >Thwarting Wi-Fi Side-Channel Analysis through Traffic Demultiplexing
【24h】

Thwarting Wi-Fi Side-Channel Analysis through Traffic Demultiplexing

机译:通过流量多路分解阻止Wi-Fi侧信道分析

获取原文
获取原文并翻译 | 示例
           

摘要

Side-channel information leaks have been reported in various online applications, especially, in wireless local area networks (WLANs) due to the shared-medium nature of wireless links and the ease of eavesdropping. Even when Wi-Fi traffic is encrypted, its characteristics are identifiable, which can be used to infer sensitive user activities and data. Existing countermeasures do not offer effective and efficient protection: packet padding and traffic morphing often bring in substantial communication overheads; attempts to anonymize user identifiers are vulnerable to the analysis based upon traffic statistics. In this paper, we present a new technique, called traffic demultiplexing, which offers effective protection against Wi-Fi traffic analysis without incurring noticeable overhead and performance degradation. Our approach utilizes Media Access Control (MAC) layer virtualization and packet scheduling over multiple virtual MAC interfaces to shape the traffic on each virtual MAC interface, so as to hide the original traffic characteristics. Traffic demultiplexing operates at the MAC layer and is transparent to users and other protocol stacks. We implemented our technique over Multiband Atheros Driver for Wi-Fi (MadWifi) and evaluated it in real WLAN environments. Our experimental study demonstrates that traffic demultiplexing is effective and efficient in defending against traffic analysis attacks and easy to deploy.
机译:由于无线链接的共享媒介性质和易于监听,在各种在线应用中,特别是在无线局域网(WLAN)中,已经报道了边信道信息泄漏。即使对Wi-Fi流量进行加密,其特征也是可以识别的,可用于推断敏感的用户活动和数据。现有的对策不能提供有效的保护:数据包填充和流量变型通常会带来大量的通信开销;对用户标识符进行匿名化的尝试很容易受到基于流量统计信息的分析的影响。在本文中,我们提出了一种称为流量多路分解的新技术,该技术可有效防止Wi-Fi流量分析,而不会引起明显的开销和性能下降。我们的方法利用媒体访问控制(MAC)层虚拟化和多个虚拟MAC接口上的数据包调度来调整每个虚拟MAC接口上的流量,从而隐藏原始流量特征。流量解复用在MAC层进行,对用户和其他协议栈透明。我们在Wi-Fi(MadWifi)的多频带Atheros驱动程序上实施了我们的技术,并在实际的WLAN环境中对其进行了评估。我们的实验研究表明,流量多路分解可以有效地防御流量分析攻击,并且易于部署。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号