Abstract: To analyze traffic in the anonymity network, an active network flow watermark scheme, the ON/OFF watermarking, is proposed to embed timing information into the network flow. This scheme exploits a technique that drops packets at prescribed time intervals to create a watermark sequence at the sending side of a flow, then extracts inter-packet delay at the receiving side, and computes the L1 distance between generated sequences to identify the network flow. A sliding window based L1 distance computation algorithm is proposed to detect flow watermark at a low overhead. Experimental results demonstrate that this timing-based flow watermarking scheme can identify watermarks efficiently and is resistant to timing disturbances in Tor.
Loading