pith. sign in

arxiv: 1403.0297 · v1 · pith:I3O4HYPAnew · submitted 2014-03-03 · 💻 cs.CR

I Know Why You Went to the Clinic: Risks and Realization of HTTPS Traffic Analysis

classification 💻 cs.CR
keywords accuracyattackhttpstrafficanalysiscachingcookiesevaluation
0
0 comments X
read the original abstract

Revelations of large scale electronic surveillance and data mining by governments and corporations have fueled increased adoption of HTTPS. We present a traffic analysis attack against over 6000 webpages spanning the HTTPS deployments of 10 widely used, industry-leading websites in areas such as healthcare, finance, legal services and streaming video. Our attack identifies individual pages in the same website with 89% accuracy, exposing personal details including medical conditions, financial and legal affairs and sexual orientation. We examine evaluation methodology and reveal accuracy variations as large as 18% caused by assumptions affecting caching and cookies. We present a novel defense reducing attack accuracy to 27% with a 9% traffic increase, and demonstrate significantly increased effectiveness of prior defenses in our evaluation context, inclusive of enabled caching, user-specific cookies and pages within the same website.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.