[论文解读] I Know Where You are and What You are Sharing: Exploiting P2P Communications to Invade Users' Privacy
本文展示了攻击者如何通过发起隐蔽的呼叫并关联网络流量,利用类似Skype的实时通信系统在NAT之后仍能追踪用户IP地址和移动模式。此外,通过结合Skype与BitTorrent,攻击者可利用IP ID验证技术,以高精度将用户身份与其文件共享活动关联起来。
In this paper, we show how to exploit real-time communication applications to determine the IP address of a targeted user. We focus our study on Skype, although other real-time communication applications may have similar privacy issues. We first design a scheme that calls an identified targeted user inconspicuously to find his IP address, which can be done even if he is behind a NAT. By calling the user periodically, we can then observe the mobility of the user. We show how to scale the scheme to observe the mobility patterns of tens of thousands of users. We also consider the linkability threat, in which the identified user is linked to his Internet usage. We illustrate this threat by combining Skype and BitTorrent to show that it is possible to determine the file-sharing usage of identified users. We devise a scheme based on the identification field of the IP datagrams to verify with high accuracy whether the identified user is participating in specific torrents. We conclude that any Internet user can leverage Skype, and potentially other real-time communication systems, to observe the mobility and file-sharing usage of tens of millions of identified users.
研究动机与目标
- 调查普通用户是否可利用实时通信系统追踪特定个体的IP地址与移动轨迹。
- 确定是否仅通过公开可用的工具与协议,即可将用户身份与其网络活动(如文件共享)关联起来。
- 评估现有VoIP客户端隐私设置在防范此类追踪攻击方面的有效性。
- 评估该追踪方案在同时追踪数万名用户时的可行性。
提出的方法
- 开发了一种方案,通过分析呼叫建立期间的独特数据包模式,从Skype数据包中识别并提取被叫方的IP地址,从而与其它对等方的流量区分开来。
- 使用地理定位服务将提取出的IP地址映射到地理位置和ISP信息。
- 通过定期发起隐蔽呼叫,观察IP地址变化,实现对用户移动轨迹的长期追踪。
- 利用IP数据报中的IP标识(IP-ID)字段,高精度验证目标用户是否参与特定BitTorrent种子。
- 结合基于Skype的用户识别与对BitTorrent追踪器公告的被动监控,将用户身份与文件共享行为关联。
- 评估了该方案在NAT环境下的鲁棒性,表明即使在NAT环境下,仍可确定用户的公网IP地址。
实验结果
研究问题
- RQ1攻击者是否仅通过标准VoIP通信,即可确定位于NAT后的目标Skype用户当前的IP地址?
- RQ2通过定期、低曝光度的呼叫,能在多大程度上长期观察目标用户的移动轨迹?
- RQ3是否仅通过网络层流量分析,无需ISP合作,即可将用户身份与其P2P文件共享活动关联?
- RQ4Skype等VoIP客户端中现有的隐私设置在防范此类追踪攻击方面有多有效?
- RQ5该追踪方案在大规模用户群体中的可扩展性如何?对用户隐私有何实际影响?
主要发现
- 作者通过分析呼叫建立期间的数据包模式,高精度地提取了位于NAT后的目标Skype用户的IP地址,即使在NAT环境下也成功实现。
- 该方案通过定期呼叫观察IP地址变化,实现了对用户长期移动轨迹的追踪,表明Skype未实施有效的防御措施。
- 该方法可同时追踪数万名用户,理论上可扩展至全球约5600万活跃Skype用户。
- 通过关联Skype与BitTorrent流量中的IP ID,作者以高度置信度验证了特定用户参与了特定文件共享会话。
- Skype现有的隐私设置对本攻击完全无效,因该方案未触发任何警报或通知。
- 该攻击引入了显著的关联性威胁,可将用户身份与其网络使用行为(如文件共享)关联,可能导致勒索或钓鱼攻击。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。