TY - GEN
T1 - What can you learn from an IP?
AU - Patil, Simran
AU - Borisov, Nikita
N1 - Publisher Copyright:
© 2019 ACM.
PY - 2019/7/22
Y1 - 2019/7/22
N2 - The Internet was not designed with security in mind. A number of recent protocols such as Encrypted DNS, HTTPS, etc. target encrypting critical parts of the web architecture, which can otherwise be exploited by eavesdroppers to infer users' data. But encryption may not necessarily guarantee privacy, especially when it comes to metadata. Emerging standards can protect the contents of both DNS queries and the TLS SNI extensions; however, it might still be possible to determine which websites users are visiting by simply looking at the destination IP addresses on the traffic originating from users' devices. We perform a measurement study to determine the anonymity provided by IP addresses resulting from the multiple sub-queries that are made as a consequence of accessing a particular web page. We show that, in most cases, an adversary can use the IP addresses during a page load as a form of a fingerprint to infer the original site identity.
AB - The Internet was not designed with security in mind. A number of recent protocols such as Encrypted DNS, HTTPS, etc. target encrypting critical parts of the web architecture, which can otherwise be exploited by eavesdroppers to infer users' data. But encryption may not necessarily guarantee privacy, especially when it comes to metadata. Emerging standards can protect the contents of both DNS queries and the TLS SNI extensions; however, it might still be possible to determine which websites users are visiting by simply looking at the destination IP addresses on the traffic originating from users' devices. We perform a measurement study to determine the anonymity provided by IP addresses resulting from the multiple sub-queries that are made as a consequence of accessing a particular web page. We show that, in most cases, an adversary can use the IP addresses during a page load as a form of a fingerprint to infer the original site identity.
UR - http://www.scopus.com/inward/record.url?scp=85074447662&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=85074447662&partnerID=8YFLogxK
U2 - 10.1145/3340301.3341133
DO - 10.1145/3340301.3341133
M3 - Conference contribution
AN - SCOPUS:85074447662
T3 - ANRW 2019 - Proceedings of the 2019 Applied Networking Research Workshop
SP - 45
EP - 51
BT - ANRW 2019 - Proceedings of the 2019 Applied Networking Research Workshop
PB - Association for Computing Machinery
T2 - 2019 Applied Networking Research Workshop, ANRW 2019
Y2 - 22 July 2019
ER -