Ερευνητικό Προσωπικό
Τακετζής Δημήτριος
Προσωπικά Στοιχεία
Τακετζής Δημήτριος
Copyright Notice: Το υλικό αυτό παρουσιάζεται για έγκαιρη διάδοση επιστημονικής και τεχνικής εργασίας. Τα πνευματικά δικαιώματα και όλα τα σχετικά δικαιώματα παραμένουν στους συγγραφείς ή σε άλλους κατόχους πνευματικών δικαιωμάτων. Όσοι αντιγράφουν αυτές τις πληροφορίες αναμένεται να τηρούν τους όρους και τους περιορισμούς που επιβάλλει το πνευματικό δικαίωμα κάθε συγγραφέα. Στις περισσότερες περιπτώσεις, τα έργα αυτά δεν μπορούν να αναδημοσιευτούν ή να αναπαραχθούν μαζικά χωρίς τη ρητή άδεια του κατόχου των πνευματικών δικαιωμάτων.
Επιστημονικά Συνέδρια
E. Mitakidis, D. Taketzis, A. Fakis, G. Kambourakis, SnoopyBot: An Android spyware to bridge the mixes in Tor, The 24th International Conference on Software, Telecommunications and Computer Networks (SoftCOM 2016), Sep, 2016, Split, Croatia, IEEE Press, http://marjan.fesb.hr/SoftCOM/2016/
Περίληψη:
We present a moderately simple to implement but very effective and silent deanonymization scheme for Tor traffic. This is done by bridging the mixes in Tor, that is, we control both the traffic leaving the Onion Proxy (OP) and the traffic entering the Exit node. Specifically, from a user’s viewpoint, our proposal has been implemented in the popular Android platform as a spyware, having the dual aim to manipulate user traffic before it enters the Tor overlay and explicitly instruct OP to choose an exit node that is controlled by the attacker. When the user traffic is received by the rogue exit node it is filtered, and the sender’s IP details become visible. Notably, apart from deobfuscating normal http traffic, say, send via the Tor browser, the proposed scheme is able to manipulate https requests as well.
We present a moderately simple to implement but very effective and silent deanonymization scheme for Tor traffic. This is done by bridging the mixes in Tor, that is, we control both the traffic leaving the Onion Proxy (OP) and the traffic entering the Exit node. Specifically, from a user’s viewpoint, our proposal has been implemented in the popular Android platform as a spyware, having the dual aim to manipulate user traffic before it enters the Tor overlay and explicitly instruct OP to choose an exit node that is controlled by the attacker. When the user traffic is received by the rogue exit node it is filtered, and the sender’s IP details become visible. Notably, apart from deobfuscating normal http traffic, say, send via the Tor browser, the proposed scheme is able to manipulate https requests as well.


Λήψη PDF