{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,14]],"date-time":"2026-04-14T23:23:15Z","timestamp":1776208995799,"version":"3.50.1"},"publisher-location":"Berlin, Heidelberg","reference-count":36,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642316791","type":"print"},{"value":"9783642316807","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-31680-7_6","type":"book-chapter","created":{"date-parts":[[2012,6,27]],"date-time":"2012-06-27T17:40:32Z","timestamp":1340818832000},"page":"100-119","source":"Crossref","is-referenced-by-count":40,"title":["Spying in the Dark: TCP and Tor Traffic Analysis"],"prefix":"10.1007","author":[{"given":"Yossi","family":"Gilad","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Amir","family":"Herzberg","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"6_CR1","unstructured":"Tor Metrics Portal. Network and Usage Graphs (November 2011), http:\/\/metrics.torproject.org\/graphs.html"},{"key":"6_CR2","unstructured":"Advanced Network Architecture Group. ANA Spoofer Project (2012), http:\/\/spoofer.csail.mit.edu\/summary.php"},{"key":"6_CR3","doi-asserted-by":"crossref","unstructured":"Allman, M., Paxson, V., Blanton, E.: TCP Congestion Control. RFC 5681 (Draft Standard) (September 2009)","DOI":"10.17487\/rfc5681"},{"key":"6_CR4","doi-asserted-by":"crossref","unstructured":"Baker, F., Savola, P.: Ingress Filtering for Multihomed Networks. RFC 3704 (Best Current Practice) (March 2004)","DOI":"10.17487\/rfc3704"},{"key":"6_CR5","doi-asserted-by":"crossref","unstructured":"Bellovin, S.M.: A Technique for Counting Natted Hosts. In: Internet Measurement Workshop, pp. 267\u2013272. ACM (2002)","DOI":"10.1145\/637241.637243"},{"key":"6_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1007\/978-3-642-15497-3_16","volume-title":"Computer Security \u2013 ESORICS 2010","author":"S. Chakravarty","year":"2010","unstructured":"Chakravarty, S., Stavrou, A., Keromytis, A.D.: Traffic Analysis against Low-Latency Anonymity Networks Using Available Bandwidth Estimation. In: Gritzalis, D., Preneel, B., Theoharidou, M. (eds.) ESORICS 2010. LNCS, vol.\u00a06345, pp. 249\u2013267. Springer, Heidelberg (2010), http:\/\/dx.doi.org\/10.1007\/978-3-642-15497-3"},{"key":"6_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1007\/11423409_3","volume-title":"Privacy Enhancing Technologies","author":"G. Danezis","year":"2005","unstructured":"Danezis, G.: The Traffic Analysis of Continuous-Time Mixes. In: Martin, D., Serjantov, A. (eds.) PET 2004. LNCS, vol.\u00a03424, pp. 35\u201350. Springer, Heidelberg (2005)"},{"key":"6_CR8","doi-asserted-by":"crossref","unstructured":"Deering, S., Hinden, R.: Internet Protocol, Version 6 (IPv6) Specification. RFC 2460 (Draft Standard), Updated by RFCs 5095, 5722, 5871, 6437 (December 1998)","DOI":"10.17487\/rfc2460"},{"key":"6_CR9","doi-asserted-by":"crossref","unstructured":"Dierks, T., Rescorla, E.: The Transport Layer Security (TLS) Protocol Version 1.2. RFC 5246 (Proposed Standard), Updated by RFCs 5746, 5878, 6176 (2008)","DOI":"10.17487\/rfc5246"},{"key":"6_CR10","doi-asserted-by":"crossref","unstructured":"Dingledine, R., Mathewson, N., Syverson, P.F.: Tor: The Second-Generation Onion Router. In: USENIX Security Symposium, pp. 303\u2013320. USENIX (2004)","DOI":"10.21236\/ADA465464"},{"key":"6_CR11","doi-asserted-by":"crossref","unstructured":"Ehrenkranz, T., Li, J.: On the State of IP Spoofing Defense. ACM Transactions on Internet Technology (TOIT)\u00a09(2) (2009)","DOI":"10.1145\/1516539.1516541"},{"key":"6_CR12","unstructured":"Evans, N.S., Dingledine, R., Grothoff, C.: A Practical Congestion Attack on Tor Using Long Paths. In: USENIX Security Symposium, pp. 33\u201350. USENIX Association (2009)"},{"key":"6_CR13","doi-asserted-by":"crossref","unstructured":"Felten, E.W., Schneider, M.A.: Timing Attacks on Web Privacy. In: Jajodia, S. (ed.) Proceedings of the 7th ACM Conference on Computer and Communications Security, Greece, pp. 25\u201332. ACM Press (November 2000)","DOI":"10.1145\/352600.352606"},{"key":"6_CR14","doi-asserted-by":"crossref","unstructured":"Ferguson, P., Senie, D.: Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing. RFC 2827 (Best Current Practice), Updated by RFC 3704 (May 2000)","DOI":"10.17487\/rfc2827"},{"key":"6_CR15","unstructured":"Gilad, Y., Herzberg, A.: Fragmentation Considered Vulnerable: Blindly Intercepting and Discarding Fragments. In: Proceedings of USENIX Workshop on Offensive Technologies (August 2011)"},{"key":"6_CR16","doi-asserted-by":"crossref","unstructured":"Gilad, Y., Herzberg, A.: Spying in the Dark: TCP and Tor Traffic Analysis - Technical Report (April 2012), http:\/\/u.cs.biu.ac.il\/~herzbea\/security\/TR\/TR12_02","DOI":"10.1007\/978-3-642-31680-7_6"},{"key":"6_CR17","doi-asserted-by":"crossref","unstructured":"Gont, F.: Security Assessment of the Internet Protocol Version 4. RFC 6274 (Informational) (July 2011)","DOI":"10.17487\/rfc6274"},{"key":"6_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"171","DOI":"10.1007\/3-540-36467-6_13","volume-title":"Privacy Enhancing Technologies","author":"A. Hintz","year":"2003","unstructured":"Hintz, A.: Fingerprinting Websites Using Traffic Analysis. In: Dingledine, R., Syverson, P.F. (eds.) PET 2002. LNCS, vol.\u00a02482, pp. 171\u2013178. Springer, Heidelberg (2003)"},{"key":"6_CR19","doi-asserted-by":"crossref","unstructured":"Kadloor, S., Gong, X., Kiyavash, N., Tezcan, T., Borisov, N.: Low-Cost Side Channel Remote Traffic Analysis Attack in Packet Networks. In: ICC, pp. 1\u20135. IEEE (2010)","DOI":"10.1109\/ICC.2010.5501972"},{"key":"6_CR20","doi-asserted-by":"crossref","unstructured":"Kent, S., Seo, K.: Security Architecture for the Internet Protocol. RFC 4301 (Proposed Standard) (December 2005)","DOI":"10.17487\/rfc4301"},{"key":"6_CR21","doi-asserted-by":"crossref","unstructured":"Killalea, T.: Recommended Internet Service Provider Security Services and Procedures. RFC 3013 (Best Current Practice) (November 2000)","DOI":"10.17487\/rfc3013"},{"key":"6_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"104","DOI":"10.1007\/3-540-68697-5_9","volume-title":"Advances in Cryptology - CRYPTO \u201996","author":"P.C. Kocher","year":"1996","unstructured":"Kocher, P.C.: Timing Attacks on Implementations of Diffie-Hellman, RSA, DSS, and Other Systems. In: Koblitz, N. (ed.) CRYPTO 1996. LNCS, vol.\u00a01109, pp. 104\u2013113. Springer, Heidelberg (1996)"},{"key":"6_CR23","doi-asserted-by":"crossref","unstructured":"Larsen, M., Gont, F.: Recommendations for Transport-Protocol Port Randomization. RFC 6056 (Best Current Practice) (January 2011)","DOI":"10.17487\/rfc6056"},{"key":"6_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"251","DOI":"10.1007\/978-3-540-27809-2_25","volume-title":"Financial Cryptography","author":"B.N. Levine","year":"2004","unstructured":"Levine, B.N., Reiter, M.K., Wang, C.-X., Wright, M.: Timing Attacks in Low-Latency Mix Systems. In: Juels, A. (ed.) FC 2004. LNCS, vol.\u00a03110, pp. 251\u2013265. Springer, Heidelberg (2004)"},{"key":"6_CR25","unstructured":"Lyon, G.: Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning (2009), http:\/\/nmap.org\/book\/"},{"key":"6_CR26","doi-asserted-by":"crossref","unstructured":"Mittal, P., Khurshid, A., Juen, J., Caesar, M., Borisov, N.: Stealthy Traffic Analysis of Low-Latency Anonymous Communication Using Throughput Fingerprinting. In: Chen, Y., Danezis, G., Shmatikov, V. (eds.) ACM Conference on Computer and Communications Security, pp. 215\u2013226. ACM (2011)","DOI":"10.1145\/2046707.2046732"},{"key":"6_CR27","doi-asserted-by":"crossref","unstructured":"Murdoch, S.J., Danezis, G.: Low-Cost Traffic Analysis of Tor. In: IEEE Symposium on Security and Privacy, pp. 183\u2013195. IEEE Computer Society (2005)","DOI":"10.1109\/SP.2005.12"},{"key":"6_CR28","doi-asserted-by":"publisher","first-page":"103","DOI":"10.1145\/2046556.2046570","volume-title":"Proceedings of the 10th Annual ACM Workshop on Privacy in the Electronic Society, WPES 2011","author":"A. Panchenko","year":"2011","unstructured":"Panchenko, A., Niessen, L., Zinnen, A., Engel, T.: Website Fingerprinting in Onion Routing Based Anonymization Networks. In: Proceedings of the 10th Annual ACM Workshop on Privacy in the Electronic Society, WPES 2011, pp. 103\u2013114. ACM, New York (2011)"},{"key":"6_CR29","unstructured":"Postel, J.: Transmission Control Protocol. RFC 793 (Standard), Updated by RFCs 1122, 3168, 6093, 6528 (September 1981)"},{"key":"6_CR30","doi-asserted-by":"crossref","unstructured":"Pries, R., Yu, W., Fu, X., Zhao, W.: A New Replay Attack Against Anonymous Communication Networks. In: IEEE International Conference on Communications (ICC), pp. 1578\u20131582 (2008)","DOI":"10.1109\/ICC.2008.305"},{"key":"6_CR31","unstructured":"Sanfilippo, S.: A New TCP Scan Method (1998), http:\/\/seclists.org\/bugtraq\/1998\/Dec\/79"},{"key":"6_CR32","unstructured":"Sanfilippo, S.: About the IP Header ID (December 1998), http:\/\/www.kyuzz.org\/antirez\/papers\/ipid.html"},{"key":"6_CR33","unstructured":"Wikipedia. Usage Share of Operating Systems (2011), http:\/\/en.wikipedia.org\/wiki\/Usage_share_of_operating_systems"},{"key":"6_CR34","unstructured":"Zalewski, M.: Silence on the wire: a field guide to passive reconnaissance and indirect attacks. No Starch Press (2005)"},{"key":"6_CR35","unstructured":"Zander, S., Murdoch, S.J.: An Improved Clock-Skew Measurement Technique for Revealing Hidden Services. In: van Oorschot, P.C. (ed.) USENIX Security Symposium, pp. 211\u2013226. USENIX Association (2008)"},{"key":"6_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1007\/11423409_13","volume-title":"Privacy Enhancing Technologies","author":"Y. Zhu","year":"2005","unstructured":"Zhu, Y., Fu, X., Graham, B., Bettati, R., Zhao, W.: On Flow Correlation Attacks and Countermeasures in Mix Networks. In: Martin, D., Serjantov, A. (eds.) PET 2004. LNCS, vol.\u00a03424, pp. 207\u2013225. Springer, Heidelberg (2005)"}],"container-title":["Lecture Notes in Computer Science","Privacy Enhancing Technologies"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-31680-7_6.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,2]],"date-time":"2025-04-02T19:52:47Z","timestamp":1743623567000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-31680-7_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642316791","9783642316807"],"references-count":36,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-31680-7_6","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012]]}}}