  • ISSN号:1000-9825
  • 期刊名称:《软件学报》
  • 分类:TP391.4[自动化与计算机技术—计算机应用技术;自动化与计算机技术—计算机科学与技术]
  • 作者机构:[1]东南大学计算机科学与工程学院,江苏南京211189
  • 相关基金:国家重点基础研究发展计划(973)(2010cB328104);国家自然科学基金(61272054,61202449,61070161,61003257,60903162);国科技支撑计划(2010BA188B03,2011BAK21802);国家核高基科技重大专项(软件类)项目(2010ZX01044-001-001);高等学校博士点专项科研基金(20110092130002);江苏省自然科学基金(BK2008030);江苏省网络与信息安全重点实验室资助项目(BM2003201);教育部计算机网络与信息集成重点实验室(东南大学)资助项目(93K.9)



Abuse of anonymous communication systems has introduced new challenges into network administration. The effective identification of anonymous communication traffic is a prerequisite to prevent such abuse; thus, this is fundamentally important for both theoretical researches and practical applications. Existing researches mainly focus on the confirmation of anonymous communication relationship and cannot be used to identify and block anonymous communication traffic. To solve this problem, the operation mechanism is deeply analyzed and traffic characteristics are summarized for the widely used Tor anonymous communication system. On this basis, a TLS fingerprint-based and packet-size distributions based methods are proposed to identify Tor anonymous communication traffic, respectively. The advantages, disadvantages and applicability of these two methods are analyzed and discussed in detail, and are validated by CAIDA dataset and online deployment. Experimental results prove that both methods are effective in identifying Tot anonymous communication traffic.

