Fingerprinting Websites Using Traffic Analysis by Andrew Hintz (also SafeWeb Vunerability)

download Fingerprinting Websites Using Traffic Analysis by Andrew Hintz (also SafeWeb Vunerability)

of 8

Transcript of Fingerprinting Websites Using Traffic Analysis by Andrew Hintz (also SafeWeb Vunerability)

  • 8/7/2019 Fingerprinting Websites Using Traffic Analysis by Andrew Hintz (also SafeWeb Vunerability)

    1/8

    ! ! $ ! ' 0 1 3 5 0 8 @ ! !

    D E F H P R S U E V X

    Y ` a c e f h i q s h

    i u u v w x x f h i q s h

    y y

    j k m n o m

    z { | z {W z } {

    {

    y z {W z z z

    } { | {

    z | { z

    z z z

    | |

    | | |

    D V P E H V U E E U F P V P E V P E V F V P E V E V P E V P H E P V P P

    V P E H P V V V P E H V U E F P E V U F P P P H V U E P F P P F H U E

    E E P E H V P F E P H V U E E VQ U V P R U E U V U E E F R

    F V U P U E V H E P H H P F H P P P P E P E H V U E R P H U

    E P H P V E V V V V E P F E P U U E V V P E V

    P E H V P F F V V V U V H E P H H P F U E P H b U U V d R E P P F H P H

    P H E P E V V V P U V P P P U V U E U V H U E H P U U V U E P H V U E

    R P U V P U E P H b U U V P P E P b U P P E V P F E E P V

    R H E F E H P P F E E P E V U H P E V H S R P P H V P H P H P P P H

    H V U P V F V V E P P F V F P V P H V P V U E V V U E P H

    b U U V

    P H P E U V H U E V P E V H P E F P U H V H H V P H V E U V

    E V P E V U E R E V H E U H E U d R H P d

    R P E P E H V P F V H E F E E P E H V P F V H U U P P E

    P E H V U E P V F F E V V H V V P V P E V F V

    P U E V H E U V V P F P P V U V H E U E d V P E V E

    R V P H P P U P H E F P E F P H V P F V U V R F V R V H E

    P H H P F E P H V U E U V V U E E V V P H U E E R P F P V P E V F V

    V H E P H H P F E P F U V H H P V

    P P U E P E H V U E R P H V V V P V V H V P V U V P H H

    V V P R P U V P V P H P P U E E F H E E P R U E U V H U E

  • 8/7/2019 Fingerprinting Websites Using Traffic Analysis by Andrew Hintz (also SafeWeb Vunerability)

    2/8

    V P U H E P V R H E E P V U E V V V P V V U F P V P U F P E V U V U P U V P H H V P

    R P P H P H V V V P H P P U E V F P V U E V E U E R P P

    H P P V E P U V P H V H P R H U V U E V P E V U d P U E E

    V P E V S R P P H P U d H V P F

    H U V E P P F U U R P U V P V

    U H P E V V U V P H V P V U E H U F P F P P

    P P V V P V V H P P E V P E P R U E U V H U E V P E P V R H

    P P P H H F P V P H U E U E R V V P P H U U P R U E V P U E V U E

    E F

    H U V V P E H V R P P E V P E V E F V P H V P P

    P U E U P R P F V P P H P P V U E V V P H E U V H U E V P E P V R H

    E E P V U E E P E F P H E E V F P V P H U E P V P V E V P E V H V V V P

    P H U U P R U E D V F P V P H V P V V P E V P E V V P F V

    F P E V F P V P H F U E V V H E U

    P E P H U U V V U R P P V P F R E F P P H P D P H F R E

    F V P S P H V P R P P U P U E F P F U E V P P E F V P H P P H

    P E P F V P P P V H P P U P H U U V P F " R P P V R R R E E

    V P R F F R E F P H H V P H V P P # V P P H V P P

    U P U X P R U U H V P V H V E V E V

    P E P H U P R R P P U E P P V P VQ U F R E F V P

    P U V P F R U V V P P E V U H R P H U H V E V P H E P V

    # H P H ' P P E R P E U E P P P P U H P V H E P F U P H V P )

    E E P V U E P P P P U V H E P H H P F U E P H V P ) E E P V U E P

    P U H P V H E P F E P H V P H V V V P P H " V P H E F U V U U V P P

    H E V V P H V F P V P H U E P V P U X P P P P U E H P V H E P F V V P P P

    P H D V P V V P H V F U E V V P E P H V P V V H P P U E P E V

    V P H V E V P P P P H " V P H

    P E P R P H P V E U V H V P E P V R H P P P H V P U U V P F

    R P U V P V P P P F H P H R F P P V F P V P H U E P V P E P H E F V P

    H U V P U X P V P P V V P H H P P U P F H P P V P P P F H P H

    R F E R V V V P P H H P V P F H E E P V U E V V P H P P U P F H P P V U P

    2 3 V P 6 7 V P 2 3 V P E F 3 6 V P # V P P V H E P H U X P

    F U H P V H H P E F R U V V P U X P P H V U E P V V R H P P U P F V P P H

    P P V V H E P H U X P H U P E R P P H U P V V P " E P H H U E V

    P P R U V H P E P H H U V P R P P P

    E P H H U E V V V H P P F E F U A P H P E V U X P P H P P U E U P E

    E P H H U E V V P H P H V P E P V V V P E P H H U E V R U P E U P P V " F

    U P V U V P V P E P H F U A P H P E V U P E P H H U E V H U E V H P

    U V P V V P H P E V H U R P E E P H V U P P V U V P V V

    V P H P H P 2 F U A P H P E V P U E V P P P V " V V P V P P P

    H E F U X P P V R P P E ' 2 2 V P E F ' 2$ 2 $ 2 V P U P E V V V P H P H P

    H U V P 7 '4 2 $ 2 F U A P H P E V U X P V V P V P 2 F U A P H P E V P E P

    U U E 7 ' 2 2 V V P 2 V R P H U P V V V P H P H P P H 2 V V P F H F

    F U A P H P E V U P E P H H U E V U E P H U H P H V E V P V V

  • 8/7/2019 Fingerprinting Websites Using Traffic Analysis by Andrew Hintz (also SafeWeb Vunerability)

    3/8

    E P H R P P H H P E V E V P R H F R U F P R P S R P P H H P P P H V V

    V P 2 V V P F H F E P H E b U P V R P U V P V V P H U V P 2

    P U V P F R U V V P P U V P V V H P H P S E F F E V H P P H P E P

    E V P H P H U R F H E V P E U P E P H H U E V

    U U P P U E H H P U P V U V P V P H P R F P E V 7 ' 2 2

    F U A P H P E V E P H H U E V H R P U V P V V H P P F E E P P P H P H P

    P H V U E H P V E 7 '4 2 $ 2 V P V E R P P E V P R H F R U F P R P E V

    V P E P H H U E V H V P V E R P P H P E U P

    P P H P H E P E V V P R H F E U F P H V P U P R U E P H V U E E V P E V E V P

    E V P H E P V V P U P H P P V P U E P P P H E P E V E U F P H V P U P R U E

    E F U U F P E V g U V U U F P V P U P 7 P P V P U E P P P H E P E V

    E V H E V P H E P V E E P V U E U E V E F V V P E V H V P E E V E

    E U V H E V P H E P V E U V U E R U V V P H V U F P U E V

    E V U F P U V P P U E P P P H E P E V P F R P U V P

    V P E F V P P R H U P ' D E P P P U V

    U H P E V V U U E R P U V P P P P P U F P V V P E V P E V

    E F V P V P E U V P P U E U U V P F V P U E P P P H E P E V E E V

    P U V P R V R P U V P E P P P H U E U E U U P R U E

    U E V P H P U P E V U E P F P U X P E P H H U E V U E V P V P P H E

    P E V F P E P H V P E P H H U E V H U P R P U V P V V U V E R V

    V F V P E R V V H H V P P E P H H U E V P H R P V H V

    V P H E U P E V V V P E P H H U E V H E E P F R P U V P H P V P E E R E V

    P U P R U E V P E E P F R P U V P D V V P P H E P E V R F P P

    E V V H V E X P V V V H H U P E P H H V U E

    E V P H E P V V H D V P P H E P E V R F P V P H U F U d P E P H V P E P R

    E P H H U E V P P E P F U V P H P E P R U V P R P E V P E V E P

    H P P E V

    E H F P H V V P V V P P U b U U V V P E P H H U E V V V F P U F P F V V d

    U P P E V V P V V E H F P H V U P P E V V P V V H V H P V P F H

    H V V E X P V F E F P E P H V P E P H H U E V V P V V

    V H U E V P P H H H P V P V P E P H H U E V V U E V P V

    V E V V V F V V V U P E V V V P P H E P V P P H " H V

    P V F E P P E P H V P F E V P H R U E E U V H V P

    V H P U E P E V V V P P P P H " V P H P U P P E V V U E V P

    V V E F P R P P V F P H P U P E R P U V P V

    i u u v w x x f h i q s h x v ` a u x u x " a c a # x

    D E P P H P P P H U U V U E E E E P P H % 4 2 $ 2

    V P g R U E E P H H U E V R P E P H V P F '

  • 8/7/2019 Fingerprinting Websites Using Traffic Analysis by Andrew Hintz (also SafeWeb Vunerability)

    4/8

    a w h s u w

    a w h s u w

    a w h s u w

    7 U E P F V P P P E H P P F

    a w h s u w

    a w h s u w

    a w h s u w

    u u s h # a ` " Y " " a ` a s u a w #

    U X P U V P E V F V U E V P H P P U P F E P U H V E F E V U V P

    E P H V U P V U P U F V U X P R P P E U E V P P

    P E P H H U E V U E H H E F P V P H U E P R U U H V R F U A P H P E V E

    P H H U E V H P V F P V U E V U E V P E P H P V P U X P V P U E

    V R E P H H U E V S P H P H P V P H P V R P E H U E V P E P H H U E V V R

    F U A P H P E V P H U U V U E E E P R H H V '

    $ h # a ` " s s a u s s u i a " a & s s q & w

    $ h # a ` " s s a u s s u i a " a & s s q & w

    $ h # a ` " a 0 u u i a w

    S P H P U V P V V H U E P H U U V U E E E R U V P H U U V U E

    '

    $ h # a ` " s s a u s s u i a " a & s s q & w

    $ h # a ` " s s a u s s u i a " a & # # q q h 3 & w

    $ h # a ` " a 0 u u i a w

    P P H P R P H P V P V P F V P H U V V V P F P P U E P H H U E V P F

    P P P U E P F R P H P E E E V U P F V H E F

    R U E V E V U U V P F P V P P P U E U H V E V P H E P V # H P H

    ' U E P P E F P V P H V P V F P U V P U U V P F D V

    E H V P H H P P V P F V P P H P R U V F U A P H P E V V P H U P R U E V P

    P R P P

    P E H P F V P E P H H U E V H U V P V V R P H P V P P V P d P V

    E P H P V V P E F R P d P V V P V E E P V U E

    H V U R ' V ' ' E V P H R H F V P V 7 ' 5 V P E E P V U E R P H P

    R P V V P U V P V R E P H H U E V R P H P V P P R P U V P S R P P H

    V U d F ' 5 V P U X P R P H P P V V P

    P P E P H E P P R P E H P F V V P E P H P P

    U X P V P H P F P E P H H U E V P U V P V P E P H H U E V

    P F U A P H P E V U V P P V E P H P P U X P V P V V V R P E

    H U E E P H H U E V F U A P H P E V U V P R P H P V P H P E V P P

    P U X P V P V V V E E U P E H U E R % 5 S R P P H H U V P

    V V R P H P F U A P H P E V d E P U V P H 2 H V P H H P F

    P P U E U V U H P V R V V U V U U P V U U E P H H U E V R P

    P E P E H F P H V F P V P H U E P V P F U V E P H H U E V U E

  • 8/7/2019 Fingerprinting Websites Using Traffic Analysis by Andrew Hintz (also SafeWeb Vunerability)

    5/8

    R P P E P H H P P H V P H V P V E P P F V P F E P # V P E U P H P

    P V P V P E V P V P P E F E P P P P P V F R E U V H P P R P

    H U E P H U P

    D V V P U V V V V P P E F P H U P F U U P E V H V U E

    E P H H U E V E P V P V V E P P F V P U H P F U E H F P H H U V

    V R H E H P P P H P H P P P H V U E R U E P F E P V U H P

    V P E P H H U E V V V U E V P P P H

    " # % ' ( 03 2 ' 0 5 6 8 0 A B A A 5 A

    P E P H U U V R P P V P H V P V P d F R E F U V P S

    P H V P R P P V V V P H P U U V U E P P H " H R P H V P E H P V H

    V P S P E F H P P V E H P P H P E P F P H U E F V P P P V

    # H V U H H R P H d H P P V H P P H P E P F P H H V U H R P P

    U E V P P H F P H D E V V P H F V P V U U E V E V E F P V P E V E

    V P U X P V P V H E U U E V V P H F P H U E R U V P H E E U F P

    U V V U E U E V V P H F P H V H E U U E R F U E H P P V P E U P E P

    P R U V V R P E V P V V R P E V V H U H V 2 V V P % V

    R P H S R P P H U E H F P H V V P U F E V P V U U H P P E V E

    V V P H R F P V P E P H V P P P H E P H H U E V H P R P U V P P P

    V P V V P H R F E P P F E P H P F U A P H P E V R P H R U E H H

    D F B I 0 5 Q " S 0 ' # 5 5 6 # % ' X " ' 0 I 0 #

    P H P H P P P H V U E V V E P F E P U E H F P H V U H P V P H

    V P H P V U E V P U E U V U E P H H U E V P P P E P H H U E V V P E U E P H P E V

    U E F P P E U P U V R F P P E P U V P V U P P V F V U E H F P H

    V P E P H V P H P H V P E P H H U E V b E P R V U F P F E P U V V P

    P P H E P H H U E V V P P R P U V P U P R P F H F U A P H P E V V P H D

    V P P E P H H U E V F V P E P F F P F V P V P H D E P U X P R U H

    P U E U E P H V U P F V P E P E U F P H P F V P E H V P P

    U X P E F U E F P F U E V P E P H H U E V R U U V d P F H V P V V

    c e g I 2 " X " ' 0 I 0 # A # 5 e # 0 ' q ' s A # ' A

    D E V P H U F P H U H U E V P H E F P V P E P V P V V U V

    P E F V P E P V E P H H U E V H t V E P R P P V E P E V U H P R P U V P

    P E P H U U V R P U V P V P V P E V U P U U V P P H P V V P P

    U V P D E V V P H F V P V U U E V E V H P V U E E P H H U E V R U

    E V U E V P P U X P H P R U H P U P H P H V U E R P U V P

    H P P E P H H U E V H V P E E R P U V P F U E F P E V E

    V P P U V P F R U V V P U E P V V P P V V H P U V P F

  • 8/7/2019 Fingerprinting Websites Using Traffic Analysis by Andrew Hintz (also SafeWeb Vunerability)

    6/8

    R U V E Pr U E P F V H V P U E P b E P V U E V V F P E V U P F U

    V V V R P U V P H P E H U E F V P P P V E P P H P

    E V P U V P P E P H U U V V U P P E V P P R P U V P V P P H

    V P E P V P H U V V V P P H P F F R E F P F E F V P H P H P F

    E V E P P F V H P F R E F V P H U U V P F R U V P U E F U U F P

    F B I 0 5 Q " # % "

    b E P R V U H P V U E V R E P H H U E V V P V P H U V E V H P U H P V R P

    U X P V P P V V P P U E H F P H V P V H P P U V F P

    P F V V U V R P " U X P H P R U V U E ' V P P V P H V P E V P H P

    U U H P E E F H P H V P P P E H F P H V P P U V U U H P

    V P V V U P P E V P F V U H E P V U E P V F P H E P V U E

    H H H V H V P V V H P P V U V V P H P U E U E U X P V V

    P E V P V P P E V P F U V H U X P V V H P V P H V E F V P

    V P V V H P V E V U E P V U P H P E V U U V H P P V P P U P F H E P

    S R P P H U E V P V F V V U H E P V U E F F P F H V R U P E P

    U V U P U V F U F H H P V V P

    P H P H P P P H H V U P V F V V E P P F V P H V P V U E V

    R P U V P E P H H U E V U E P V P P V P U P P E V P F V P R P H

    E F P E P U P P E V P F V P P E F P H

    2 2 " 5 A ' # 5 8 0

    b E P R H V P V U E U E V E P H H U E V U E U H V P H V F F P V H E U P V

    V P F V V V U V H P V H E V V P P H P P V F F F U E E U P F P H U P F P H P

    H P U H P V P H V F U V P F V P H P H P V H E U E U V V V P P H D V

    V U H P V U E P H H E P U V P P H P F F U P V P S V V

    U V H P V H E H P H V V U E V P E V P R P P V V U V H P V H E V V P

    P H

    5 2 6 ' A 5 6 S 5 ' # 5 A

    P R P H F F F P V H H E F U X P F

    F V V V P P V V U V H P V H E V V P P H U P V H F V E P F P V V

    U V F P E V V P H V P P H E P V P R P P V V V P P H U P R H P

    P H E F U X P F P E V F P F F P F U E V P P H S P t V

    V P H V P V V V V P P U E E U E V P F P E V E U P H V

    ) # d R H U P U X P F P E V P H P H E F P V H E P

    F V V V U F F P F V P P V P H P V P V H P U X P V P P R U P

    H P F S R P P H F F U E P V H F V V V H E U U E R U U E H P P V P E V

    E F R U F V V V U H P U H P F

  • 8/7/2019 Fingerprinting Websites Using Traffic Analysis by Andrew Hintz (also SafeWeb Vunerability)

    7/8

    2 2 e g # 0 X ' S 5 ' # 5 A

    E H F P H V R P H V P P H P E V P E E P

    V U E R U V E P H H U E V V P R P H F F F U E P V H H E F

    U X P F E E P V U E V F F V U U E P H V U E H E F U X P F U P U P

    V H E H P E V H U U E V V P S F P E V P P P V H H U R F P

    V P A P V U P U F F P F V H V V P P P F V V V U E V P V

    V P P U E E U E H P E F V P P U U P P H P P E P H H U E V V P H

    R F H H V P E F F F U E P V H E E P V U E V

    V P P U E E U E H P E F V H E U U E R F E V P V H P V P

    V P S R P P H V U P V F P P H F H R U H V F F U E P P E

    H U V P R P P F F U H V V P U E V P E F P F V V P P

    D F F U E U E U E V E P H U X P P V H E E P V U E R F H P U H P

    U E U E V E V P V H E F R U F V H P P U E H F P H V V V P P H

    P E V P V P U E V P H R F P V H U V P F P V P

    E V E F R U F V V V U V P

    D ' 2 ' B s ' 0 5 6 X ' A 8 0 A 6 ' 0 0 ' 2

    H U E F P V U E P P P H F P V E V U P R H U

    E V P R P P V V V P U U V U V U E U H P F U P U E V R P

    H R P H U E E V V U P R H U P H R F F H V U d F P H P P V P

    E P H P H P P U P F H V R P P H P P U P H U U V P F E E

    R U V H U V H E P F A V P R F F R E F P V E ' 5 V P E P H P

    V V V P R F P F R E F P F U V P F U P R P F V P U V P R U V H U

    V H E P F E P E P H P V H E P H H P F F P H P F P F P P E H V P H

    F U b U E V U E V P P P V E F D V U P E V H U P V F R F

    P P E P H H U E V P P H E P H P U X P E F V P H P H P V

    U P E V E U P S R P P H V U R F H P P P H P U E E P E U P E P V

    P H P P V P R F E V P P V U P R E H U E V P R P P V V

    V P U U V

    c 8 0 A 6 ' 0 e Q ' 0 # % " ( ' S 5 ' # 5

    D E V P H H V H V P V U E U E V E P H H U E V U E U V P U V F U V H

    E V V P H V F P V P H U E P V P U X P P P P U E V H E P H H P F U E

    V P P V P V P H P H P H P P R P V F R U U V P V U U P b E P

    P V F U H C U P E V V E V P E V U P E E P V U E V V P P R P P H P H

    P H P U U E F R H P U V H P V V U E H U H V E V P H E P V # H P H ' R U

    P V V P U E P H U V E P E E P V U E V E U P E R P P H P H

    S R P P H V U P V V U E F P E V P P V P E P A P V R P E H R U E V P R P

    U E P P D V V U V P E U P R F P U V H P F U V H E

    V V P H V E F V P U X P P P P U E V H E P H H P F U V VQ U P U P V

    E F V P U X P P P U E V V P V U U E V P P V V H E P H H P F

    P P H P H P V P b U U V V H P V H E R P P E F U V P F P

    U E U E P V H V V P P H U E V U P V F U V R F P U U P H

    E V V P H V F P V P H U E P V P U X P P U E F U U F P S R P P H E P U V P H

    H R P H E H R P P H P H P V U b U U V

  • 8/7/2019 Fingerprinting Websites Using Traffic Analysis by Andrew Hintz (also SafeWeb Vunerability)

    8/8

    D V P P U E E P H P E V V P U V P U F P H P P E V P F E P

    b U P F V V P H P E H V P F R P H U P P U P V V V P U X P F V U V P E

    E V V P F V U H V H U P V U E V P P U E U E F U E

    H P V P H V E H U P H P P V P H P U E P H b U U V U E P P H U E

    S R P H P E V V P H R V U E E E P V U E E F P V P H U E P V P U X P V P

    R H F P U E P F U U F P V V P V V V V P U X P V P R H F U E V

    V P F F

    R F U P V V E H R E E F ) H V P U H P H P

    P E V V V U P H R F 9 U P V V E V P P P V P P H

    H U F U E P H P P H U P V V P P E V U H P E V P H E P V E U V

    } ! # % ' ) 0 # 3 4 % 7 9 A z | }

    D D G H I D

    I

    Q Q {

    R

    S | U | | } z S X } {

    X } y z Y

    I ` ` I

    ` ` R

    b

    } S {

    I ` ` I

    y c |

    } e 9 g

    } }

    I ` ` I

    i 9 c Y b

    Y z

    r s s t u v v x x x r v r v s v s r s

    } b Y z 9 } # k l m

    r s s t u v v x x x x v x v t s v o o o r s

    G

    } { c } z z c Y z

    i

    I ` `

    r s s t u v v x v t t r s

    {

    S } S |

    g

    y | } ~ 0 ~ 3 % m m ) % m ' # ) m 3 ~ | } ~ 0

    ' ' 3 m 7

    `

    } e 9

    g

    } }

    I ` ` H I

    R

    c } b l z | } { z | z z {

    | z z |

    } }

    { { | | } { {

    G