Tor serves as a widely adopted anonymous communication network, highly valued by privacy advocates, journalists, and whistleblowers seeking to maintain anonymity. While its primary use is for anonymous website access, recent research has revealed the feasibility of anonymous Voice over IP (VoIP) calls over Tor. However, due to the distinctive characteristics of VoIP and Tor’s inability to conceal its metadata, VoIP traffic remains vulnerable to detection. We address this challenge by proposing a defense to effectively conceal VoIP flows from detection. We begin by showing a simple throughput-based heuristic is sufficient to detect VoIP traffic through Tor. To counter this vulnerability, we initially attempted to obscure VoIP’s identifiable throughput characteristics by interspersing VoIP packets with HTTP traffic over the same Tor circuit. However, this approach proved inadequate against advanced machine learning (ML) and deep learning (DL) detection techniques. Consequently, we developed an advanced defense mechanism that manipulates timing and throughput-related features to make VoIP traffic resemble regular HTTP downloads. We also developed and deployed multiple ML and DL models to test and validate this defense rigorously. Notably, this defense strategy successfully evaded detection by these models (viz., detection rate dropped from 95% to 20%) without significantly degrading VoIP call quality, as verified by PESQ (Perceptual Evaluation of Speech Quality) measurements ( \( \text {Average PESQ} \approx 2.5 \) ). Our findings indicate that this approach provides a robust solution for safeguarding VoIP communications on Tor against sophisticated traffic analysis attacks, ensuring voice quality.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

VoIP Vanguard: A Practical Front Line Defense Against VoIP Identification Attacks in Tor

  • S. Jithin,
  • Richa Gupta,
  • Reeshabh Kumar Ranjan,
  • Shreyansh Nagpal,
  • Mukulika Maity,
  • Sambuddho Chakravarty

摘要

Tor serves as a widely adopted anonymous communication network, highly valued by privacy advocates, journalists, and whistleblowers seeking to maintain anonymity. While its primary use is for anonymous website access, recent research has revealed the feasibility of anonymous Voice over IP (VoIP) calls over Tor. However, due to the distinctive characteristics of VoIP and Tor’s inability to conceal its metadata, VoIP traffic remains vulnerable to detection. We address this challenge by proposing a defense to effectively conceal VoIP flows from detection. We begin by showing a simple throughput-based heuristic is sufficient to detect VoIP traffic through Tor. To counter this vulnerability, we initially attempted to obscure VoIP’s identifiable throughput characteristics by interspersing VoIP packets with HTTP traffic over the same Tor circuit. However, this approach proved inadequate against advanced machine learning (ML) and deep learning (DL) detection techniques. Consequently, we developed an advanced defense mechanism that manipulates timing and throughput-related features to make VoIP traffic resemble regular HTTP downloads. We also developed and deployed multiple ML and DL models to test and validate this defense rigorously. Notably, this defense strategy successfully evaded detection by these models (viz., detection rate dropped from 95% to 20%) without significantly degrading VoIP call quality, as verified by PESQ (Perceptual Evaluation of Speech Quality) measurements ( \( \text {Average PESQ} \approx 2.5 \) ). Our findings indicate that this approach provides a robust solution for safeguarding VoIP communications on Tor against sophisticated traffic analysis attacks, ensuring voice quality.