{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,18]],"date-time":"2025-12-18T14:00:01Z","timestamp":1766066401813},"reference-count":56,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2014,8,18]],"date-time":"2014-08-18T00:00:00Z","timestamp":1408320000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2015,6]]},"DOI":"10.1007\/s10207-014-0256-7","type":"journal-article","created":{"date-parts":[[2014,8,17]],"date-time":"2014-08-17T03:50:22Z","timestamp":1408247422000},"page":"205-220","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":18,"title":["Detection and analysis of eavesdropping in anonymous communication networks"],"prefix":"10.1007","volume":"14","author":[{"given":"Sambuddho","family":"Chakravarty","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Georgios","family":"Portokalidis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michalis","family":"Polychronakis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Angelos D.","family":"Keromytis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2014,8,18]]},"reference":[{"key":"256_CR1","unstructured":"Anonymizer, Inc. http:\/\/www.anonymizer.com\/"},{"key":"256_CR2","unstructured":"Anonymouse. http:\/\/anonymouse.org\/"},{"key":"256_CR3","doi-asserted-by":"crossref","unstructured":"Back, A., M\u00f6ller, U., Stiglic, A.: Traffic analysis attacks and trade-offs in anonymity providing systems. In: Proceedings of the 4th International Workshop on Information Hiding(IHW), pp. 245\u2013257. Springer, London (2001)","DOI":"10.1007\/3-540-45496-9_18"},{"key":"256_CR4","unstructured":"Known bad relays. https:\/\/trac.torproject.org\/projects\/tor\/wiki\/doc\/badRelays"},{"key":"256_CR5","unstructured":"Balsa\u2014An e-mail client for GNOME. http:\/\/balsa.gnome.org\/"},{"key":"256_CR6","doi-asserted-by":"crossref","unstructured":"Bauer, K., McCoy, D., Grunwald, D., Kohno, T., Sicker, D.: Low-resource routing attacks against tor. In: Proceedings of the 2007 ACM Workshop on Privacy in Electronic Society (WPES), pp. 11\u201320 (2007)","DOI":"10.1145\/1314333.1314336"},{"key":"256_CR7","doi-asserted-by":"crossref","unstructured":"Bauer, K., McCoy, D., Grunwald, D., Sicker, D.: Bitblender: light-weight anonymity for bittorrent. In: Proceedings of the workshop on Applications of private and anonymous communications, AIPACa \u201908, pp. 1:1\u20131:8. ACM, New York, NY, USA (2008) doi: 10.1145\/1461464.1461465","DOI":"10.1145\/1461464.1461465"},{"key":"256_CR8","unstructured":"Bennett, K., Grothoff, C.: Gnunet: gnu\u2019s decentralized anonymous and censorship-resistant P2P framework. http:\/\/gnunet.org\/"},{"key":"256_CR9","doi-asserted-by":"crossref","unstructured":"Bennett, K., Grothoff, C.: GAP\u2014practical anonymous networking. In: Proceedings of the Privacy Enhancing Technologies Workshop (PET), pp. 141\u2013160 (2003)","DOI":"10.1007\/978-3-540-40956-4_10"},{"key":"256_CR10","unstructured":"Bowen, B.M., Hershkop, S., Keromytis, A.D., Stolfo, S.J.: D-cubed. http:\/\/sneakers.cs.columbia.edu\/ids\/RUU\/Dcubed\/"},{"key":"256_CR11","doi-asserted-by":"crossref","unstructured":"Bowen, B.M., Hershkop, S., Keromytis, A.D., Stolfo, S.J.: Baiting inside attackers using decoy documents. In: Proceedings of the 5th International ICST Conference on Security and Privacy in Communication Networks (SecureComm), pp. 51\u201370 (2009)","DOI":"10.1007\/978-3-642-05284-2_4"},{"key":"256_CR12","doi-asserted-by":"crossref","unstructured":"Bowen, B.M., Kemerlis, V.P., Prabhu, P., Keromytis, A.D., Stolfo, S.J.: Automating the injection of believable decoys to detect snooping. In: Proceedings of the Third ACM Conference on Wireless Network Security (WiSec), pp. 81\u201386 (2010)","DOI":"10.1145\/1741866.1741880"},{"key":"256_CR13","doi-asserted-by":"crossref","first-page":"22","DOI":"10.1109\/MSP.2009.109","volume":"7","author":"BM Bowen","year":"2009","unstructured":"Bowen, B.M., Salem, M.B., Hershkop, S., Keromytis, A.D., Stolfo, S.J.: Designing host and network sensors to mitigate the insider threat. IEEE Secur. Priv. 7, 22\u201329 (2009). doi: 10.1109\/MSP.2009.109","journal-title":"IEEE Secur. Priv."},{"key":"256_CR14","unstructured":"Chakravarty, S., Polychronakis, M., Portokalidis, G., Keromytis, A.D.: Details of various eavesdropping incidents. http:\/\/dph72nibstejmee4.onion\/decoys_via_tor\/map.html"},{"key":"256_CR15","doi-asserted-by":"crossref","unstructured":"Charavarty, S., Portokalidis, G., Polychronakis, M., Keromytis, A.D.: Detecting traffic snooping in tor using decoys. In: Proceedings of the 14th International Symposium on Recent Advances in Intrusion Detection, pp. 222\u2013241 (2011)","DOI":"10.1007\/978-3-642-23644-0_12"},{"issue":"2","key":"256_CR16","doi-asserted-by":"crossref","first-page":"84","DOI":"10.1145\/358549.358563","volume":"24","author":"DL Chaum","year":"1981","unstructured":"Chaum, D.L.: Untraceable electronic mail, return addresses, and digital pseudonyms. Commun. ACM 24(2), 84\u201390 (1981)","journal-title":"Commun. ACM"},{"key":"256_CR17","unstructured":"Claws mail. http:\/\/www.claws-mail.org"},{"key":"256_CR18","unstructured":"Desaster: kippo ssh honeypot. http:\/\/code.google.com\/p\/kippo"},{"key":"256_CR19","doi-asserted-by":"crossref","unstructured":"D\u00edaz, C., Seys, S., Claessens, J., Preneel, B.: Towards measuring anonymity. In: Proceedings of the 2nd International Conference on Privacy Enhancing Technologies. PET\u201902, pp. 54\u201368. Springer, Berlin (2003)","DOI":"10.1007\/3-540-36467-6_5"},{"key":"256_CR20","unstructured":"Dingledine, R., Mathewson, N.: Tor path specification. https:\/\/gitweb.torproject.org\/torspec.git?a=blob_plain;hb=HEAD;f=path-spec.txt"},{"key":"256_CR21","unstructured":"Dingledine, R., Mathewson, N., Syverson, P.: Onion Routing. http:\/\/www.onion-router.net\/"},{"key":"256_CR22","doi-asserted-by":"crossref","unstructured":"Dingledine, R., Mathewson, N., Syverson, P.: Tor: the second-generation onion router. In: Proceedings of the 13th USENIX Security Symposium, pp. 303\u2013319 (2004)","DOI":"10.21236\/ADA465464"},{"key":"256_CR23","doi-asserted-by":"crossref","unstructured":"Douceur, J.R.: The sybil attack. In: Proceedings of International Workshop on Peer-to-Peer Systems (2001)","DOI":"10.1007\/3-540-45748-8_24"},{"key":"256_CR24","unstructured":"Stenberg, D.: kippo curl. http:\/\/curl.haxx.se"},{"key":"256_CR25","unstructured":"Evolution. http:\/\/projects.gnome.org\/evolution"},{"key":"256_CR26","unstructured":"Firesheep. http:\/\/codebutler.com\/firesheep"},{"key":"256_CR27","unstructured":"The Honeynet Project. http:\/\/www.honeynet.org\/"},{"key":"256_CR28","unstructured":"I2P Anonymous Network. http:\/\/www.i2p2.de\/"},{"key":"256_CR29","unstructured":"iOpus $$^{\\rm TM}$$ TM : iMacros $$\\copyright $$ \u00a9 . http:\/\/www.iopus.com\/imacros\/"},{"key":"256_CR30","doi-asserted-by":"crossref","unstructured":"Isdal, T., Piatek, M., Krishnamurthy, A., Anderson, T.: Privacy-preserving P2P data sharing with oneswarm. In: Proceedings of the Conference on Applications, Technologies, Architectures, and Protocols for Computer Communications (SIGCOMM), pp. 111\u2013122 (2010)","DOI":"10.1145\/1851275.1851198"},{"key":"256_CR31","unstructured":"JAP. http:\/\/anon.inf.tu-dresden.de\/"},{"key":"256_CR32","unstructured":"Kmail\u2014mail client. http:\/\/kde.org\/applications\/internet\/kmail"},{"key":"256_CR33","unstructured":"McCanne, S., Leres, C., Jacobson, V.: Tcpdump and libpcap. http:\/\/www.tcpdump.org\/"},{"key":"256_CR34","doi-asserted-by":"crossref","unstructured":"Mccoy, D., Bauer, K., Grunwald, D., Kohno, T., Sicker, D.: Shining light in dark places: understanding the tor network. In: Proceedings of the 8th International Symposium on Privacy Enhancing Technologies (PETS), pp. 63\u201376 (2008)","DOI":"10.1007\/978-3-540-70630-4_5"},{"key":"256_CR35","unstructured":"Meyers, J.: IMAP4 ACL extension. http:\/\/www.ietf.org\/rfc\/rfc2086.txt"},{"key":"256_CR36","doi-asserted-by":"crossref","unstructured":"Mulazzani, M., Huber, M., Weippl, E.R.: Tor HTTP usage and information leakage. In: Proceedings of the IFIP Conference on Communications and Multimedia Security (CMS), pp. 245\u2013255 (2010)","DOI":"10.1007\/978-3-642-13241-4_22"},{"key":"256_CR37","unstructured":"Palfrader, P.: Tor SSL MITM check. http:\/\/svn.noreply.org\/svn\/weaselutils\/trunk\/tor-exit-ssl-check"},{"key":"256_CR38","unstructured":"Pound, C.: Chris Pound\u2019s language machines. http:\/\/www.ruf.rice.edu\/~pound\/"},{"key":"256_CR39","unstructured":"Pound, C.: Language confluxer. http:\/\/www.ruf.rice.edu\/~pound\/new-lc\/"},{"key":"256_CR40","unstructured":"Pound, C.: Prop. http:\/\/www.ruf.rice.edu\/~pound\/prop"},{"key":"256_CR41","unstructured":"Provos, N.: A virtual honeypot framework. In: Proceedings of the 13th USENIX Security Symposium, pp. 1\u201314 (2004)"},{"key":"256_CR42","doi-asserted-by":"crossref","unstructured":"Raymond, J.F.: Traffic analysis: protocols, attacks, design issues, and open problems. In: Proceedings of Designing Privacy Enhancing Technologies: Workshop on Design Issues in Anonymity and Unobservability, pp. 10\u201329. Springer, LNCS 2009 (2000)","DOI":"10.1007\/3-540-44702-4_2"},{"key":"256_CR43","doi-asserted-by":"crossref","first-page":"482","DOI":"10.1109\/49.668972","volume":"16","author":"MG Reed","year":"1998","unstructured":"Reed, M.G., Syverson, P.F., Goldschlag, D.M.: Anonymous connections and onion routing. IEEE J. Sel. Areas Commun. 16, 482\u2013494 (1998)","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"256_CR44","doi-asserted-by":"crossref","first-page":"66","DOI":"10.1145\/290163.290168","volume":"1","author":"MK Reiter","year":"1998","unstructured":"Reiter, M.K., Rubin, A.D.: Crowds: anonymity for web transactions. ACM Trans. Inf. Syst. Secur. 1, 66\u201392 (1998)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"256_CR45","unstructured":"Services, O.U.C.: The university of oxford text archive. http:\/\/ota.ahds.ac.uk\/"},{"key":"256_CR46","unstructured":"Spitzner, L.: Honeytokens: the other honeypot. http:\/\/www.symantec.com\/connect\/articles\/honeytokens-other-honeypot"},{"key":"256_CR47","doi-asserted-by":"crossref","unstructured":"Spitzner, L.: Honeypots: catching the insider threat. In: Proceedings of the 19th Annual Computer Security Applications Conference (ACSAC) (2003)","DOI":"10.1109\/CSAC.2003.1254322"},{"issue":"5","key":"256_CR48","doi-asserted-by":"crossref","first-page":"484","DOI":"10.1145\/42411.42412","volume":"31","author":"C Stoll","year":"1988","unstructured":"Stoll, C.: Stalking the wily hacker. Commun. ACM 31(5), 484\u2013497 (1988)","journal-title":"Commun. ACM"},{"key":"256_CR49","volume-title":"The cuckoo\u2019s egg: tracking a spy through the maze of computer espionage","author":"C Stoll","year":"1989","unstructured":"Stoll, C.: The cuckoo\u2019s egg: tracking a spy through the maze of computer espionage. Doubleday, New York (1989)"},{"key":"256_CR50","unstructured":"Sylpheed-lightweight and user-friendly e-mail client. http:\/\/sylpheed.sraoss.jp\/en"},{"key":"256_CR51","unstructured":"Furry, T.: TOR exit-node doing MITM attacks. http:\/\/www.teamfurry.com\/wordpress\/2007\/11\/20\/tor-exit-node-doing-mitm-attacks\/"},{"key":"256_CR52","unstructured":"Tor metrics portal. http:\/\/metrics.torproject.org\/"},{"key":"256_CR53","unstructured":"Tor metrics portal: number of users. http:\/\/metrics.torproject.org\/users.html"},{"key":"256_CR54","unstructured":"Ts\u2019o, T.: Password generator. http:\/\/sourceforge.net\/projects\/pwgen\/"},{"key":"256_CR55","unstructured":"Winter, P., Lindskog, S.: Spoiled onions: exposing malicious tor exit relays. Technical Report, Karlstad University (2014). URL http:\/\/veri.nymity.ch\/spoiled_onions\/techreport.pdf"},{"key":"256_CR56","doi-asserted-by":"crossref","unstructured":"Yuill, J., Zappe, M., Denning, D., Feer, F.: Honeyfiles: deceptive files for intrusion detection. In: Proceedings of the 2nd IEEE Workshop on Information Assurance (WIA), pp. 116\u2013122 (2004)","DOI":"10.1109\/IAW.2004.1437806"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-014-0256-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-014-0256-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-014-0256-7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,14]],"date-time":"2019-08-14T02:28:26Z","timestamp":1565749706000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-014-0256-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,8,18]]},"references-count":56,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2015,6]]}},"alternative-id":["256"],"URL":"https:\/\/doi.org\/10.1007\/s10207-014-0256-7","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,8,18]]}}}