본문

서브메뉴

Application Awareness in Censorship Circumvention Systems
Application Awareness in Censorship Circumvention Systems
Application Awareness in Censorship Circumvention Systems

상세정보

자료유형  
 학위논문 서양
최종처리일시  
20250211152128
ISBN  
9798384050377
DDC  
004
저자명  
Sun, Zhen.
서명/저자  
Application Awareness in Censorship Circumvention Systems
발행사항  
[Sl] : Cornell University, 2024
발행사항  
Ann Arbor : ProQuest Dissertations & Theses, 2024
형태사항  
132 p
주기사항  
Source: Dissertations Abstracts International, Volume: 86-03, Section: B.
주기사항  
Advisor: Shmatikov, Vitaly.
학위논문주기  
Thesis (Ph.D.)--Cornell University, 2024.
초록/해제  
요약Internet censorship circumvention systems rely on cover applications to conceal the existence of their communication: covert data is tunneled through the encrypted network channel of the cover applications to provide network-level unobservability. However, recently proposed systems are not aware of the cover application semantics, making them vulnerable to adversaries that can observe the application-level behavior of cover applications. In this thesis, I present my Ph.D. research on new classes of attacks on censorship circumvention systems that exploit the lack of application awareness in existing designs, as well as the mitigation of these attacks.We first demonstrate a new type of active attack we call "differential degradation." These attacks exploit the discrepancies between the network requirements of the cover application and those of the circumvention system, allowing adversaries to detect and block state-of-the-art systems that resist network traffic analysis-based attacks. Differential degradation doesn't require complex multi-flow measurement or traffic classification, making it feasible for realistic censors at low cost. I'll also discuss the root causes of these vulnerabilities and the trade-offs faced by designers of circumvention systems.Then, we show how a network-based adversary is able to observe a cover application's events through encrypted traffic flows, and thus can detect the violation of application-specific invariants caused by tunneling data through the cover application using popular content substitution designs. To mitigate the problem, we propose non-disruptive content substitution that does not introduce inconsistencies into the application state. Using this idea, we design and implement Telepath, a Minecraft-based covert communication system that is immune to our attacks while providing resistance to traditional traffic analysis attacks.
일반주제명  
Computer science
일반주제명  
Computer engineering
키워드  
Internet censorship
키워드  
Semantics
키워드  
Traffic classification
키워드  
Network traffic
기타저자  
Cornell University Computer Science
기본자료저록  
Dissertations Abstracts International. 86-03B.
전자적 위치 및 접속  
로그인 후 원문을 볼 수 있습니다.

MARC

 008250123s2024        us                              c    eng  d
■001000017163043
■00520250211152128
■006m          o    d                
■007cr#unu||||||||
■020    ▼a9798384050377
■035    ▼a(MiAaPQ)AAI31482931
■040    ▼aMiAaPQ▼cMiAaPQ
■0820  ▼a004
■1001  ▼aSun,  Zhen.▼0(orcid)0009-0002-7535-501X
■24510▼aApplication  Awareness  in  Censorship  Circumvention  Systems
■260    ▼a[Sl]▼bCornell  University▼c2024
■260  1▼aAnn  Arbor▼bProQuest  Dissertations  &  Theses▼c2024
■300    ▼a132  p
■500    ▼aSource:  Dissertations  Abstracts  International,  Volume:  86-03,  Section:  B.
■500    ▼aAdvisor:  Shmatikov,  Vitaly.
■5021  ▼aThesis  (Ph.D.)--Cornell  University,  2024.
■520    ▼aInternet  censorship  circumvention  systems  rely  on  cover  applications  to  conceal  the  existence  of  their  communication:  covert  data  is  tunneled  through  the  encrypted  network  channel  of  the  cover  applications  to  provide  network-level  unobservability.  However,  recently  proposed  systems  are  not  aware  of  the  cover  application  semantics,  making  them  vulnerable  to  adversaries  that  can  observe  the  application-level  behavior  of  cover  applications.  In  this  thesis,  I  present  my  Ph.D.  research  on  new  classes  of  attacks  on  censorship  circumvention  systems  that  exploit  the  lack  of  application  awareness  in  existing  designs,  as  well  as  the  mitigation  of  these  attacks.We  first  demonstrate  a  new  type  of  active  attack  we  call  "differential  degradation."  These  attacks  exploit  the  discrepancies  between  the  network  requirements  of  the  cover  application  and  those  of  the  circumvention  system,  allowing  adversaries  to  detect  and  block  state-of-the-art  systems  that  resist  network  traffic  analysis-based  attacks.  Differential  degradation  doesn't  require  complex  multi-flow  measurement  or  traffic  classification,  making  it  feasible  for  realistic  censors  at  low  cost.  I'll  also  discuss  the  root  causes  of  these  vulnerabilities  and  the  trade-offs  faced  by  designers  of  circumvention  systems.Then,  we  show  how  a  network-based  adversary  is  able  to  observe  a  cover  application's  events  through  encrypted  traffic  flows,  and  thus  can  detect  the  violation  of  application-specific  invariants  caused  by  tunneling  data  through  the  cover  application  using  popular  content  substitution  designs.  To  mitigate  the  problem,  we  propose  non-disruptive  content  substitution  that  does  not  introduce  inconsistencies  into  the  application  state.  Using  this  idea,  we  design  and  implement  Telepath,  a  Minecraft-based  covert  communication  system  that  is  immune  to  our  attacks  while  providing  resistance  to  traditional  traffic  analysis  attacks.
■590    ▼aSchool  code:  0058.
■650  4▼aComputer  science
■650  4▼aComputer  engineering
■653    ▼aInternet  censorship
■653    ▼aSemantics
■653    ▼aTraffic  classification
■653    ▼aNetwork  traffic
■690    ▼a0984
■690    ▼a0464
■71020▼aCornell  University▼bComputer  Science.
■7730  ▼tDissertations  Abstracts  International▼g86-03B.
■790    ▼a0058
■791    ▼aPh.D.
■792    ▼a2024
■793    ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17163043▼nKERIS▼z이  자료의  원문은  한국교육학술정보원에서  제공합니다.

미리보기

내보내기

chatGPT토론

Ai 추천 관련 도서


    신착도서 더보기
    최근 3년간 통계입니다.

    소장정보

    • 예약
    • 소재불명신고
    • 나의폴더
    • 우선정리요청
    • 비도서대출신청
    • 야간 도서대출신청
    소장자료
    등록번호 청구기호 소장처 대출가능여부 대출정보
    TF13348 전자도서 대출가능 마이폴더 부재도서신고 비도서대출신청 야간 도서대출신청

    * 대출중인 자료에 한하여 예약이 가능합니다. 예약을 원하시면 예약버튼을 클릭하십시오.

    해당 도서를 다른 이용자가 함께 대출한 도서

    관련 인기도서

    로그인 후 이용 가능합니다.