A website fingerprinting defense method based on an adversarial generative network

Through adversarial generation network and dynamic bandwidth mechanism, false data packets are generated to cover up the original traffic characteristics, which solves the shortcomings of existing website fingerprint defense solutions in defense performance and targeting, and realizes efficient anonymous network user privacy protection.

CN118890210BActive Publication Date: 2025-10-17SOUTHEAST UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411200227.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-29
Publication Date
2025-10-17
Estimated Expiration
2044-08-29

AI Technical Summary

Technical Problem

Existing website fingerprint defense solutions have deficiencies in defense performance and targeting, especially in the face of deep website fingerprint attacks. In addition, there are high packet delays or excessive data overhead during the deployment process, and the lack of consideration of prior knowledge leads to unreasonable deployment assumptions.

Method used

Adversarial generative network technology is used to generate false data packets through training generators. Combined with dynamic bandwidth mechanisms, network traffic patterns are obfuscated, defense samples are generated, original traffic characteristics are concealed, defense costs are reduced, and defense effects are enhanced.

Benefits of technology

It achieves effective defense against website fingerprint attacks, improves defense performance, reduces defense costs, enhances the privacy protection capabilities of anonymous network users, and ensures user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118890210B_ABST
    Figure CN118890210B_ABST
Patent Text Reader

Abstract

The application provides a website fingerprint defense method based on an adversarial generative network, first collects sensitive website access traffic of network users as a traffic dataset, trains an adversarial generative network, generates a traffic mode of a website, randomly takes other website traffic modes as defense targets, adjusts the difference between the size of a cache area and the defense targets by using a dynamic bandwidth mechanism, and confuses deep website fingerprint attacks in this way. The application achieves the purpose of defense by confusing network traffic mode information. The application can resist website fingerprint attacks based on deep neural networks and achieves the effect of protecting the privacy and safety of user browsing. The application trains a traffic adversarial generative network according to network traffic generated by network users, generates traffic modes of each website traffic from the angle of traffic bursts and traffic burst time intervals, adjusts the traffic by using a dynamic bandwidth mechanism, and confuses the traffic modes. The application can realize intelligent confusion of website traffic and solves the problem of privacy protection of webpage access in an anonymous network.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of network security, and particularly relates to a website fingerprint defense method based on an adversarial generative network. BACKGROUND

[0002] With people using the Internet more and more frequently for work and entertainment, network monitoring has become a common threat to people's privacy. In order to protect user privacy, the anonymous network Tor based on onion routing has become one of the most popular privacy-enhancing technologies. It prevents public association disclosure between servers and clients by routing traffic using layered encrypted chain relays (i.e. circuits). However, the privacy of Tor can be compromised by a traffic analysis method called website fingerprinting. In website fingerprinting, a local eavesdropper identifies the websites visited by a web browser client by passively observing and collecting side-channel information of the network traffic of the web browser client, such as packet size, packet timestamp and packet order, etc. (website fingerprinting does not require decryption).

[0003] In order to resist website fingerprinting attacks, researchers have proposed a variety of defense measures. The current defense methods have high packet delay or large data overhead, affecting user experience, the deployment of some defense methods relies on prior information of web access, which is often difficult to obtain in advance in actual situations, and some lightweight website fingerprint defense methods have poor defense effect when facing deep website fingerprint attacks. Many website fingerprint defense schemes have been proposed, which mask or confuse the characteristics of a sensitive traffic by filling with false packets. However, these defense methods only consider global traffic sequence statistical information, and lack of personalized filling design for specific protected traffic. Therefore, the current proposed website fingerprint defense schemes have deficiencies in defense performance and pertinence. SUMMARY

[0004] The application aims to solve the deficiencies of the current proposed website fingerprint defense schemes in defense performance and pertinence, and provides a website fingerprint defense method based on an adversarial generative network. The method generates traffic patterns of each website traffic from the perspective of traffic burst and traffic burst interval based on an adversarial generative network, adjusts the traffic through a dynamic bandwidth mechanism, confuses the network traffic pattern information, and successfully resists website fingerprint attacks based on deep neural networks. The method realizes intelligent confusion of website traffic and solves the problem of privacy protection of web access in an anonymous network.

[0005] TECHNICAL SCHEME

[0006] The website fingerprint defense method based on an adversarial generative network comprises the following steps:

[0007] The application discloses a website fingerprint defense method based on an adversarial generative network. s The website traffic pattern w s 1 The website traffic of other websites is taken as a defense shaping target during the defense, a dynamic bandwidth mechanism is utilized, and false data packets are added to make w s into a defense sample w s ′ capable of resisting website fingerprint attacks. The generation process of the defense sample w s ′ comprises the following steps:

[0008] Step (1), a traffic processing mechanism

[0009] Collecting network traffic: network access traffic is collected by using a packet capturing tool, the captured traffic is converted and saved in a specific format of five tuples, common features such as the number of request packets and the number of corresponding packets are designed according to expert knowledge, and each piece of traffic is labeled with the corresponding website.

[0010] Extracting the direction and time features of data packets in network traffic: the data packet sending direction from two kinds of senders is extracted, one part of the data packets in the network traffic is sent by the client, and the other part is sent by the server.

[0011] Converting the extracted data packet direction features in network traffic into burst form: the burst form is defined as a continuous data packet sequence in the same direction, the data packet sending direction information in the burst form is composed of the number of data packets contained in each burst, and the burst time information in the burst form is composed of the time stamp of the first data packet contained in each burst, and the burst time interval is defined as the difference of the burst time information.

[0012] Step (2), training of the traffic pattern generator

[0013] The adversarial generative network is trained using website traffic burst data, the traffic pattern of each website traffic is generated from two aspects of traffic burst and traffic burst time interval, a deep website fingerprint classifier is simultaneously trained in the training process, used for guiding the training of the generator and accelerating the convergence of the adversarial generative network: the website fingerprint classifier is composed of a convolutional neural network, so as to realize higher accuracy; the adversarial generative network is trained, and a generator capable of generating various website traffic burst data is obtained.

[0014] Step (3), selection of a traffic shaping target

[0015] The generator obtained by training is utilized to generate traffic burst data of each sensitive website, and a random traffic pool is formed. A traffic burst data is randomly extracted from the pool and taken as a traffic shaping target w t .

[0016] Step (4), dynamic bandwidth mechanism

[0017] According to the difference between the actual flow and the flow shaping target, a dynamic bandwidth mechanism is constructed, which is a normalization mechanism, a probability skipping mechanism and a dynamic control mechanism respectively;

[0018] Step (5), real-time filling algorithm

[0019] According to the timestamp, direction, size and other information, false data packets are generated; and according to the dynamic bandwidth mechanism, part of the false data packets are filled in the original flow w s , so that the burst in the original flow tends to the target flow, and part of the characteristics of the target flow are matched with the original flow to become a new defense sample w s ′.

[0020] As a further improvement of the application, the network flow burst and burst time interval in step 2 are used as training data to train the adversarial generation network as a subsequent flow pattern generator; the training target of the adversarial generation network is to train a generator that can generate realistic data distribution, that is:

[0021]

[0022] Wherein, is the distribution of false data, is the distribution of real data, is the linear interpolation point of real data and false data, and the corresponding distribution is The output of is the logarithm of the probability that the input is real, which is called log probability. The first two terms represent the discriminator trying to maximize the log probability between the real samples and the false samples of each potential generator, and the generator trying to minimize this probability. The third term is a regularization term to make satisfy the Lipschitz constraint.

[0023] The generator and the discriminator are both multilayer perceptrons, and the input of the generator is two vectors of burst size and direction and burst time interval respectively, and two generators are trained;

[0024] While training the adversarial generation network, a deep neural network is trained to guide the generation of the generator simultaneously, and the deep neural network is composed of a convolutional neural network, and the loss function is a cross-entropy function;

[0025] The attacker network uses real trajectories and generated trajectories for training, extracts the corresponding burst sequence and interval sequence from the trajectories as the input of the corresponding attacker network, and the attacker network uses cross-entropy loss for training.

[0026] As a further improvement of the present application, the specific process of selecting the target flow in step 3 is:

[0027] The generator trained in step 2 is used to generate traffic burst and burst interval data of different websites as a defense target flow pool. When defense is performed, traffic burst data is randomly extracted from the pool as the target flow for traffic shaping.

[0028] As a further improvement of the present application, in step 4, the dynamic bandwidth mechanism, when defense is performed, due to the diversity of traffic between different websites, traffic shaping without modification will cause huge bandwidth consumption. In order to control bandwidth consumption, it is divided into three modules, namely normalization, probability skipping and dynamic control module.

[0029] Normalization module: compare the size of the buffer area at this time with the size of the traffic shaping target each time to reduce the number of false data packets filled in the blank, avoid filling a large number of meaningless false data packets in the blank time in practice, ensure the randomness of the sending size to ensure the effect of defense, and reduce the retention of data packets in the buffer area, slow down the problem of data timeout, unable to normally load the page caused by the retention of data packets to be sent in practice in the buffer area. This module has two parameters, α0 and α1, and α0 < α1, α = α1-(α1-α0)*(p'-1), where p' = max(1, p'), p' is the ratio of the number of false data packets sent to real data packets, and the reference burst is b f , the size of the buffer area is b u , and after defense, the size after defense is b s :

[0030]

[0031] Probability skipping module: when the size of the data packet in the buffer area is 0, there is a certain probability of skipping this time of sending false data packets. The purpose is to avoid filling a large number of meaningless data packets in the blank time, to enhance the defense effect by reducing the frequency of false data packets filled in the blank and increasing randomness.

[0032] Dynamic control module: calculate the number of false data packets filled and the ratio of real data packets before each filling, and calculate the ratio of the sending direction (request direction) and the receiving direction (response direction) respectively to prevent the interference of data packets in opposite directions with each other's data packets and affect the defense effect.

[0033] As a further improvement of the present application, the specific process of filling data packets in step 5 is:

[0034] In defense, the burst and burst time interval are randomly generated as the reference sample, and the target of traffic shaping in defense is carried out; due to the diversity of traffic between different websites, traffic shaping without change will cause huge bandwidth overhead; by using the dynamic bandwidth mechanism, when filling each time, according to the cache data packets in the real-time cache area and the shaping target, part of the false data packets in the original traffic are filled, the burst contained in the original traffic is shaped to the target traffic, part of the characteristics of the target traffic is matched with the original traffic, and the new defense traffic is obtained. Beneficial effects: the present application aims at the problem that the existing website fingerprint defense lacks consideration of priori knowledge acquisition, resulting in unreasonable deployment assumption, combines the adversarial generative network technology, generates the sample traffic pool for defense, randomly selects the target traffic in the random traffic pool, hides the original traffic characteristics by bidirectional filling of false data packets, utilizes the dynamic bandwidth mechanism, reduces the defense cost, confuses the classifier of the website fingerprint attacker, and effectively protects the privacy security of the anonymous traffic user. The present application uses the adversarial generative network technology to enhance the deployability of the defense scheme; uses the dynamic bandwidth control technology to reduce the bandwidth overhead and time delay cost caused by the deployment of the defense, and enhances the user browsing experience. BRIEF DESCRIPTION OF DRAWINGS

[0035] Figure 1 It is the overall flowchart of the present application.

[0036] Figure 2 It is the training schematic diagram of the traffic mode generator in the present application.

[0037] Figure 3 It is the data packet filling flowchart in the present application. DETAILED DESCRIPTION

[0038] The technical scheme of the present application will be described in detail below, but the protection scope of the present application is not limited to the described embodiments.

[0039] The present application combines the adversarial generative network technology and the dynamic bandwidth control technology to confuse the website fingerprint traffic characteristics of the user. First, the traffic is grabbed as the traffic data set, then the adversarial generative network is trained, at the same time, a website fingerprint classifier with certain classification accuracy is trained to guide the generator in the adversarial generative network to better generate samples. When a network traffic needs to be protected, the generator obtained by the previous training generates the sample traffic pool for defense, randomly selects the target traffic in the random traffic pool, hides the original traffic characteristics by bidirectional filling of false data packets, utilizes the dynamic bandwidth mechanism, reduces the defense cost, and causes the classifier to be unable to accurately classify the category of the protected traffic. The present application can hide the original traffic characteristics by bidirectional filling of false data packets, confuse the classifier of the website fingerprint attacker, realize the realistic deployability premise, and protect the privacy security of the anonymous traffic user.

[0040] The application realizes effective flow filling, and further confuses the classifier of the website fingerprint attacker through the following technical features:

[0041] 1. The trained adversarial generative network can meet most defense implementation prerequisites through the generator, and the scheme deployability is increased.

[0042] 2. The application creates a dynamic bandwidth mechanism, formulates an effective filling scheme, improves the defense performance, and reduces the defense cost.

[0043] As shown in the figure, the application is a website fingerprint defense method based on an adversarial generative network, which comprises the following steps: Figure 1

[0044] Step (1), flow processing mechanism

[0045] Collect network traffic: through a packet capture tool, collect access traffic, convert and save the captured traffic into a specific format of five tuples, design common features such as request packet number and corresponding packet number according to expert knowledge, and label each traffic with the corresponding website label.

[0046] Extract the direction and time features of the data packets in the network traffic: the data packets in the network traffic are sent by the client and the server, and the sending direction of the two sending parties is extracted.

[0047] Convert the extracted data packet direction features in the network traffic into burst form: burst can be defined as a sequence of continuous data packets in the same direction, and the data packet sending direction information in burst form is composed of the number of data packets contained in each burst. The burst time information in burst form is composed of the time stamp of the first data packet contained in each burst, and the burst time interval is defined as the difference of the burst time information.

[0048] Step (2), training of the flow pattern generator

[0049] Train the adversarial generative network using website traffic burst data, generate the flow pattern of each website traffic from the two angles of traffic burst and traffic burst time interval, and simultaneously train the deep website fingerprint classifier in the training process to guide the training of the generator and accelerate the convergence of the adversarial generative network: the website fingerprint classifier is composed of a convolutional neural network to achieve higher accuracy. Train the adversarial generative network to obtain a generator that can generate various website traffic burst data.

[0050] Step (3), selection of flow shaping target

[0051] ​According to actual deployment needs, the generator trained in step 2 is used to generate traffic burst data of different websites as a defense target traffic pool. When defense is performed, traffic burst data is randomly extracted from the traffic pool as target traffic for shaping of the traffic defense.

[0052] Step (4), dynamic bandwidth mechanism

[0053] In actual application scenarios, the defense scheme needs to control the bandwidth consumption and delay consumption caused by false data packet filling. Excessive bandwidth consumption will cause the defense scheme to affect the user browsing experience, and insufficient bandwidth consumption will cause poor defense effect. In order to achieve effective defense while reducing defense cost, the defender needs to reduce defense consumption in some way.

[0054] During defense, due to the diversity of traffic between different websites, traffic shaping without modification will cause huge bandwidth overhead. In order to control bandwidth consumption, the dynamic bandwidth mechanism is divided into three modules, namely normalization, probability skipping and dynamic control modules.

[0055] Normalization module: each time filling, compare the size of the buffer area at this time with the size of the traffic shaping target, reduce the number of false data packets for blank filling, avoid filling a large number of meaningless false data packets in actual blank time. Ensure the randomness of the sending size to ensure the effect of the defense, and at the same time reduce the retention of data packets in the buffer area, slow down the problem of data timeout caused by the retention of actual data packets in the buffer area, and unable to normally load the page. This module has two parameters, α0 and α1, and α0<α1, α=α1-(α1-α0)*(p'-1), where p'=max(1,p'), p' is the number of false data packets sent and the ratio of real data packets, and the reference burst is b f , the buffer area size is b u , and after defense, the size after defense is b s :

[0056]

[0057] Probability skipping module: when the size of the data packet in the buffer area is 0, there is a certain probability of skipping this time sending false data packets. The purpose is to avoid filling a large number of meaningless data packets in the blank time, and to enhance the defense effect by reducing the frequency of false data packets for blank filling and increasing randomness.

[0058] Dynamic control module: before each filling, calculate the number of false data packets filled and the ratio of real data packets in history, and calculate the ratio of the sending direction (request direction) and the received direction (response direction) respectively. It is to prevent the interference of data packets in opposite directions to each other's data packets, which affects the defense effect.

[0059] Step (5), real-time filling algorithm

[0060] The false data packets are generated according to the timestamp, direction, size, etc. When defending, the burst and burst interval are randomly generated as the reference sample, and the target of traffic shaping when defending is shaped. Due to the diversity of traffic between different websites, traffic shaping without changes will cause huge bandwidth overhead. Using a dynamic bandwidth mechanism, each time the filling is filled, according to the real-time cache data packets and shaping targets in the cache area, part of the false data packets in the original traffic are filled, and the bursts contained in the original traffic are shaped to the target traffic. Part of the characteristics of the target traffic are combined with the original traffic to become new defense traffic.

[0061] The false data packets are meaningless virtual information. Since the client and the server use anonymous networks, the communication information is encrypted and transmitted, so the attacker cannot distinguish between false data packets and real data packets.

[0062] The other steps of the embodiment are the same as above, but the real-time filling algorithm is as shown in Figure 3 , and the specific steps are as follows:

[0063]

[0064]

[0065] The above false data packet filling algorithm is explained

[0066] Suppose there is a group of sites that need to be protected, and there is a traffic instance w s in the site. The defense method needs to fill the data packets of w s so that it becomes the traffic sequence w s ′ after defense.

[0067] w s is a sequence composed of data packet direction characteristics. The data packet can be considered to have two directions. The outgoing direction refers to the direction of the client sending data packets to the server, and the incoming direction refers to the direction of the server sending data packets to the client. The outgoing direction is expressed as +1, and the incoming direction is expressed as -1. w s can be expressed as an array composed of +1 and -1. w s can be converted into a burst form, that is, w s ={b1, b2, …, b n}, where n is the number of bursts. b i is the length of the i-th burst.

[0068] When defending, the generator first generates a number of traffic samples N to form a random traffic pool T r . When defending, a sample is randomly extracted from the sample traffic pool as a traffic shaping target, Tr = {(b1, t1), (b2, t2),..., (b n , t n )} , t i is the burst time interval form, b i is the burst form.

[0069] The cache size of the t i time period is b u , and the cache size is b u .

[0070] The number of false data packets sent is calculated, and the ratio of real data packets is calculated as a parameter p. Based on this parameter, the normalization parameter alpha and the probability skipping parameter beta are calculated respectively.

[0071] During this burst defense, a random number is generated. If the random number is greater than the probability skipping parameter beta, the correction of the current burst is abandoned, and the next burst defense is entered. Otherwise, the normalization is performed as follows.

[0072] If the current burst size b i is less than t i * alpha, the current burst correction is random(1, t i * alpha), which aims to reduce the filling of blank time. Otherwise, the correction is random(t i , b u ), which aims to increase the randomness of the defense and ensure the defense effect.

[0073] Finally, the sequence composed of b s at each iteration is the flow after defense, and the output w s ' is output.

[0074] The above embodiments show that the present application generates a small amount of false data packets in the network traffic based on the generator generated by the training traffic pattern generator, interferes with the classifier of the website fingerprint attacker, and avoids the risk of user communication information leakage. On this basis, the present application uses the adversarial generative network technology to enhance the deployability of the defense scheme; uses the dynamic bandwidth control technology to reduce the bandwidth overhead caused by deploying the defense while ensuring the defense effect and user browsing experience. The present application enhances the pertinence of the defense technology, realizes the customized protection of the flow, realizes the balance between the protection performance and the defense cost, and solves the problem of privacy protection of anonymous network users.

Claims

1. A website fingerprint defense method based on adversarial generation network, characterized in that: For any website traffic s , when defending, it takes the website traffic of other websites as the defense shaping target, uses the dynamic bandwidth mechanism, adds false data packets to make w s Become a defense sample that can resist website fingerprint attacks s '; the defense sample w s The generation process of ′ includes: Step (1), traffic processing mechanism Collecting network traffic: Using packet capture tools, we collect access traffic, convert the captured traffic into a specific five-tuple format, and save it. Based on expert knowledge, we design features for the number of request and response packets and label each traffic flow with the corresponding website. Extracting the direction and time characteristics of packets in network traffic: Some packets in network traffic are sent by the client, and the other part is sent by the server. Extract the sending direction and time characteristics of packets from both senders; The extracted packet direction features in the network traffic are converted into burst form: the burst form is defined as a sequence of continuous packets in the same direction. The packet sending direction information in the burst form consists of the number of packets contained in each burst. The burst time information in the burst form consists of the timestamp of the first packet contained in each burst. The burst time interval is defined as the difference between the burst time information. Step (2), training of traffic pattern generator Using website traffic burst data, an adversarial generative network is trained to generate traffic patterns for each website from two perspectives: traffic bursts and the time intervals between bursts. During training, a deep website fingerprint classifier is trained simultaneously to guide the training of the generator and accelerate the convergence of the adversarial generative network. The website fingerprint classifier is composed of a convolutional neural network to achieve high accuracy. The adversarial generative network is trained to obtain a generator that can generate various website traffic burst data. Step (3): Traffic shaping target selection The trained generator is used to generate traffic burst data of various sensitive websites to form a random traffic pool. A traffic burst data is randomly extracted from the pool as the traffic shaping target w t ; Step (4), dynamic bandwidth mechanism Based on the difference between actual traffic and traffic shaping targets, dynamic bandwidth mechanisms are constructed, including normalization mechanism, probabilistic skip mechanism, and dynamic control mechanism. The dynamic bandwidth mechanism in step 4, during defense, faces significant bandwidth overhead due to the diversity of traffic between different websites. To control bandwidth consumption, it is divided into three modules: normalization, probabilistic skipping, and dynamic control. Normalization module: Each time the buffer is filled, the current buffer size is compared with the size of the traffic shaping target to reduce the number of false packets in the blank filling and avoid filling a large number of meaningless false packets in the blank time. The randomness of the sending size is guaranteed to ensure the effectiveness of the defense, while reducing the retention of packets in the buffer and alleviating the problem of data timeout and failure to load the page normally caused by the packets that should be sent being retained in the buffer. This module has two parameters, α0 and α1, and α0<α1, α=α1-(α1–α0)*(p'–1), where p'=max(1,p'), p' is the ratio of the number of false packets sent to the real packets, and the reference burst is b f , the buffer size is b u , then after the defense, the size after the defense is b s : Probabilistic skip module: When the packet size in the buffer is 0, there is a probability that the sending of a false packet will be skipped. This is to avoid filling a large number of meaningless packets in the blank time, and strengthen the defense effect by reducing the frequency of false packets filled in the blank and increasing randomness. Dynamic control module: Before each filling, the ratio of the number of false data packets to the number of real data packets in the past is calculated. The ratio is calculated separately for the sending direction (request direction) and the receiving direction (response direction). This is to prevent the data packets in opposite directions from interfering with each other's data packets and affecting the defense filling effect. Step (5), real-time filling algorithm Generate fake data packets based on timestamp, direction, and size information; use dynamic bandwidth mechanism to generate fake data packets in the original traffic w s Fill some false data packets in the original traffic, shape the burst contained in the original traffic to the target traffic, and fit some characteristics of the target traffic with the original traffic to become a new defense sample w s ′.

2. A website fingerprint defense method based on adversarial generative network according to claim 1, characterized in that: In step 2, network traffic bursts and burst time intervals are used as training data to train an adversarial generative network as a traffic pattern generator for subsequent use. The training goal of the adversarial generative network is to train a generator that generates realistic data distributions, namely: in, is the distribution of false data, is the distribution of the real data, is the linear insertion point between real data and false data, and the corresponding distribution is The output of is the logarithm of the probability that the input is real, which we call log probability; the first two terms represent that the discriminator tries to maximize the log probability between the real sample and the fake sample of each potential generator, and the generator tries to minimize this probability; the third term is the regularization term, which is used to make Satisfy the Lipschitz constraint; Both the generator and the discriminator are multi-layer perceptrons. The input of the generator is two vectors: burst size direction and burst time interval. Two generators are trained. While training the adversarial generative network, we also train a deep neural network to synchronously guide the generation of the generator. The deep neural network consists of a convolutional neural network, and the loss function is the cross entropy function. The attacker network is trained using real and generated trajectories, the corresponding burst sequences and interval sequences are extracted from the trajectories as input to the corresponding attacker network, and the attacker network is trained using cross-entropy loss.

3. A website fingerprint defense method based on adversarial generative network according to claim 1, characterized in that: The specific process of selecting target traffic in step 3 is as follows: Use the generator trained in step 2 to generate traffic bursts and burst time intervals for different websites as the defense target traffic pool. When performing defense, randomly extract traffic burst data from it as the target traffic for this traffic defense shaping.

4. A website fingerprint defense method based on adversarial generative network according to claim 1, characterized in that: The specific process of filling the data packet in step 5 is as follows: During defense, bursts and time intervals are randomly generated as reference samples and the target of traffic shaping during defense. Due to the diversity of traffic between different websites, shaping traffic without modification will cause huge bandwidth overhead. Using the dynamic bandwidth mechanism, each time filling, some false data packets are filled in the original traffic based on the cached data packets in the real-time cache area and the shaping target, shaping the bursts contained in the original traffic toward the target traffic, and matching some characteristics of the target traffic with the original traffic to form a new defense sample.

Citation Information

Patent Citations

  • Multi-sample website fingerprint defense method based on adversarial sample filling

    CN118432893A

  • Network security architecture of dynamic reconfigurable system based on FPGA (Field Programmable Gate Array) and implementation method

    CN118473835A