Secure asymmetry and deployability for decoy routing systems

Censorship circumvention is often characterized as a cat-and-mouse game between a nation-state censor and the developers of censorship resistance systems. Decoy routing systems offer a solution to censor- ship resistance that has the potential to tilt this race in the favour of the censorship resist...

Full description

Bibliographic Details
Main Authors: Bocovich Cecylia, Goldberg Ian
Format: Article
Language:English
Published: Sciendo 2018-06-01
Series:Proceedings on Privacy Enhancing Technologies
Subjects:
Online Access:https://doi.org/10.1515/popets-2018-0020
id doaj-538962ff0cfa4652b97338248bfaa793
record_format Article
spelling doaj-538962ff0cfa4652b97338248bfaa7932021-09-05T13:59:52ZengSciendoProceedings on Privacy Enhancing Technologies2299-09842018-06-0120183436210.1515/popets-2018-0020popets-2018-0020Secure asymmetry and deployability for decoy routing systemsBocovich Cecylia0Goldberg Ian1Cheriton School of Computer Science, University of Waterloo, Waterloo, BelgiumCheriton School of Computer Science, University of Waterloo, Waterloo, BelgiumCensorship circumvention is often characterized as a cat-and-mouse game between a nation-state censor and the developers of censorship resistance systems. Decoy routing systems offer a solution to censor- ship resistance that has the potential to tilt this race in the favour of the censorship resistor by using real connections to unblocked, overt sites to deliver censored content to users. This is achieved by employing the help of Internet Service Providers (ISPs) or Autonomous Systems (ASes) that own routers in the middle of the net- work. However, the deployment of decoy routers has yet to reach fruition. Obstacles to deployment such as the heavy requirements on routers that deploy decoy router relay stations, and the impact on the quality of service for customers that pass through these routers have deterred potential participants from deploying existing systems. Furthermore, connections from clients to overt sites often follow different paths in the upstream and downstream direction, making some existing designs impractical. Although decoy routing systems that lessen the burden on participating routers and accommodate asymmetric flows have been proposed, these arguably more deployable systems suffer from security vulnerabilities that put their users at risk of discovery or make them prone to censorship or denial of service attacks. In this paper, we propose a technique for supporting route asymmetry in previously symmetric decoy routing systems. The resulting asymmetric solution is more secure than previous asymmetric proposals and provides an option for tiered deployment, allowing more cautious ASes to deploy a lightweight, non-blocking relay station that aids in defending against routing-capable adversaries. We also provide an experimental evaluation of relay station performance on off-the-shelf hardware and additional security improvements to recently proposed systems.https://doi.org/10.1515/popets-2018-0020censorship circumventionroute asymmetry
collection DOAJ
language English
format Article
sources DOAJ
author Bocovich Cecylia
Goldberg Ian
spellingShingle Bocovich Cecylia
Goldberg Ian
Secure asymmetry and deployability for decoy routing systems
Proceedings on Privacy Enhancing Technologies
censorship circumvention
route asymmetry
author_facet Bocovich Cecylia
Goldberg Ian
author_sort Bocovich Cecylia
title Secure asymmetry and deployability for decoy routing systems
title_short Secure asymmetry and deployability for decoy routing systems
title_full Secure asymmetry and deployability for decoy routing systems
title_fullStr Secure asymmetry and deployability for decoy routing systems
title_full_unstemmed Secure asymmetry and deployability for decoy routing systems
title_sort secure asymmetry and deployability for decoy routing systems
publisher Sciendo
series Proceedings on Privacy Enhancing Technologies
issn 2299-0984
publishDate 2018-06-01
description Censorship circumvention is often characterized as a cat-and-mouse game between a nation-state censor and the developers of censorship resistance systems. Decoy routing systems offer a solution to censor- ship resistance that has the potential to tilt this race in the favour of the censorship resistor by using real connections to unblocked, overt sites to deliver censored content to users. This is achieved by employing the help of Internet Service Providers (ISPs) or Autonomous Systems (ASes) that own routers in the middle of the net- work. However, the deployment of decoy routers has yet to reach fruition. Obstacles to deployment such as the heavy requirements on routers that deploy decoy router relay stations, and the impact on the quality of service for customers that pass through these routers have deterred potential participants from deploying existing systems. Furthermore, connections from clients to overt sites often follow different paths in the upstream and downstream direction, making some existing designs impractical. Although decoy routing systems that lessen the burden on participating routers and accommodate asymmetric flows have been proposed, these arguably more deployable systems suffer from security vulnerabilities that put their users at risk of discovery or make them prone to censorship or denial of service attacks. In this paper, we propose a technique for supporting route asymmetry in previously symmetric decoy routing systems. The resulting asymmetric solution is more secure than previous asymmetric proposals and provides an option for tiered deployment, allowing more cautious ASes to deploy a lightweight, non-blocking relay station that aids in defending against routing-capable adversaries. We also provide an experimental evaluation of relay station performance on off-the-shelf hardware and additional security improvements to recently proposed systems.
topic censorship circumvention
route asymmetry
url https://doi.org/10.1515/popets-2018-0020
work_keys_str_mv AT bocovichcecylia secureasymmetryanddeployabilityfordecoyroutingsystems
AT goldbergian secureasymmetryanddeployabilityfordecoyroutingsystems
_version_ 1717812816507830272