CCC: traffic analysis
January 3rd, 2007 by SecuriTeam, Filed under: Commentary, Encryption, Networking
the amazing steven murdoch did some traffic analysis on tor, trying to detect machines behind the annonymizing network. tor itself seems as secure as it had ever been, see comment below.
“by requesting timestamps from a computer, a remote adversary can find out the precise speed of its system clock. as each clock crystal is slightly different, and varies with temperature, this can act as a fingerprint ofthe computer and its location.”
ftp://ftp.fortunaty.net/video/23c3/wmv/timeskew2-t2s1.wmv
http://events.ccc.de/congress/2006/fahrplan/events/1513.en.html
anyone remember caida’s study on the crystals for detecting machines through nats?
http://www.caida.org/publications/papers/2005/fingerprinting/kohnobroidoclaffy05-devicefingerprinting.pdf
another good lecture on traffic analysis at ccc, which was an introduction by george danezis:
http://events.ccc.de/congress/2006/fahrplan/attachments/1185-danezistaintro.pdf
gadi evron,
ge@beyondsecurity.com.
-
http://tor.eff.org/ Shava Nerad



