about
Analyzing HTTPS Encrypted Traffic to Identify User OS, Browser and Application (arxiv.org)
5 points by e-sushi on Aug 28, 2016 | hide | past | pdf | discuss on HN

In plain words: A collection of over 20,000 samples of encrypted network traffic, labeled with the user's operating system, browser, and apps, lets a model guess those details from traffic a spy watches. It stayed above 85% accurate when network conditions changed, though less training data hurt.

Abstract · Robust Machine Learning for Encrypted Traffic Classification

Desktops and laptops can be maliciously exploited to violate privacy. In this paper, we consider the daily battle between the passive attacker who is targeting a specific user against a user that may be adversarial opponent. In this scenario, while the attacker tries to choose the best vector attack by surreptitiously monitoring the victims encrypted network traffic in order to identify users parameters such as the Operating System (OS), browser and apps. The user may use tools such as a Virtual Private Network (VPN) or even change protocols parameters to protect his/her privacy. We provide a large dataset of more than 20,000 examples for this task. We run a comprehensive set of experiments, that achieves high (above 85) classification accuracy, robustness and resilience to changes of features as a function of different network conditions at test time. We also show the effect of a small training set on the accuracy.

Amit Dvir, Yehonatan Zion, Jonathan Muehlstein, Ofir Pele, Chen Hajaj, Ran Dubin
arXiv:1603.04865 · cs.CR · submitted Mar 15, 2016 · updated Jul 20, 2020
abstract · pdf · html

add comment on HN
Also discussed: Mar 2016 (40 points, 3 comments)