{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T10:49:06Z","timestamp":1775040546460,"version":"3.50.1"},"reference-count":27,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2010,1,7]],"date-time":"2010-01-07T00:00:00Z","timestamp":1262822400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGCOMM Comput. Commun. Rev."],"published-print":{"date-parts":[[2010,1,7]]},"abstract":"<jats:p>In recent years, academic literature has analyzed many attacks on network trace anonymization techniques. These attacks usually correlate external information with anonymized data and successfully de-anonymize objects with distinctive signatures. However, analyses of these attacks still underestimate the real risk of publishing anonymized data, as the most powerful attack against anonymization is traffic injection. We demonstrate that performing live traffic injection attacks against anonymization on a backbone network is not difficult, and that potential countermeasures against these attacks, such as traffic aggregation, randomization or field generalization, are not particularly effective. We then discuss tradeoffs of the attacker and defender in the so-called injection attack space. An asymmetry in the attack space significantly increases the chance of a successful de-anonymization through lengthening the injected traffic pattern. This leads us to re-examine the role of network data anonymization. We recommend a unified approach to data sharing, which uses anonymization as a part of a technical, legal, and social approach to data protection in the research and operations communities.<\/jats:p>","DOI":"10.1145\/1672308.1672310","type":"journal-article","created":{"date-parts":[[2012,10,12]],"date-time":"2012-10-12T19:06:47Z","timestamp":1350068807000},"page":"5-11","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":51,"title":["The role of network trace anonymization under attack"],"prefix":"10.1145","volume":"40","author":[{"given":"Martin","family":"Burkhart","sequence":"first","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dominik","family":"Schatzmann","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Brian","family":"Trammell","sequence":"additional","affiliation":[{"name":"Hitachi Europe, Zurich, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Elisa","family":"Boschi","sequence":"additional","affiliation":[{"name":"Hitachi Europe, Zurich, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bernhard","family":"Plattner","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2010,1,7]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Directive 95\/46\/EC of the European Parliament and of the Council. OJ L 281 23.11.1995 p. 31 October 1995.  Directive 95\/46\/EC of the European Parliament and of the Council. OJ L 281 23.11.1995 p. 31 October 1995."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1298306.1298327"},{"key":"e_1_2_1_3_1","volume-title":"USENIX Security Symposium","author":"Bethencourt J.","year":"2005","unstructured":"J. Bethencourt , J. Franklin , and M. Vernon . Mapping internet sensors with probe response attacks . In USENIX Security Symposium , 2005 . J. Bethencourt, J. Franklin, and M. Vernon. Mapping internet sensors with probe response attacks. In USENIX Security Symposium, 2005."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1456441.1456448"},{"key":"e_1_2_1_5_1","volume-title":"IASTED International Conference on Communications and Computer Networks","author":"Brekne T.","year":"2005","unstructured":"T. Brekne and A. \u00c5rnes . Circumventing IP-address pseudonymization . In IASTED International Conference on Communications and Computer Networks , 2005 . T. Brekne and A. \u00c5rnes. Circumventing IP-address pseudonymization. In IASTED International Conference on Communications and Computer Networks, 2005."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/11767831_12"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1456441.1456452"},{"key":"e_1_2_1_8_1","volume-title":"Workshop on the Economics of Information Security (WEIS)","author":"Burstein A.","year":"2007","unstructured":"A. Burstein . An Uneasy Relationship: Cyber Security Information Sharing, Communications Privacy, and the Boundaries of the Firm . In Workshop on the Economics of Information Security (WEIS) , 2007 . A. Burstein. An Uneasy Relationship: Cyber Security Information Sharing, Communications Privacy, and the Boundaries of the Firm. In Workshop on the Economics of Information Security (WEIS), 2007."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030108"},{"key":"e_1_2_1_10_1","volume-title":"Network and Distributed System Security Symposium (NDSS)","author":"Coull S.","year":"2008","unstructured":"S. Coull , C. Wright , A. Keromytis , F. Monrose , and M. Reiter . Taming the devil: Techniques for evaluating anonymized network data . In Network and Distributed System Security Symposium (NDSS) , 2008 . S. Coull, C. Wright, A. Keromytis, F. Monrose, and M. Reiter. Taming the devil: Techniques for evaluating anonymized network data. In Network and Distributed System Security Symposium (NDSS), 2008."},{"key":"e_1_2_1_11_1","volume-title":"Network and Distributed System Security Symposium (NDSS)","author":"Coull S.","year":"2007","unstructured":"S. Coull , C. Wright , F. Monrose , M. Collins , and M.K. Reiter . Playing devil's advocate: Inferring sensitive information from anonymized network traces . In Network and Distributed System Security Symposium (NDSS) , 2007 . S. Coull, C. Wright, F. Monrose, M. Collins, and M.K. Reiter. Playing devil's advocate: Inferring sensitive information from anonymized network traces. In Network and Distributed System Security Symposium (NDSS), 2007."},{"key":"e_1_2_1_12_1","volume-title":"33rd meeting of the North American Network Operator's Group (NANOG 33)","author":"Dietrich D.","year":"2005","unstructured":"D. Dietrich . Bogons and bogon filtering . In 33rd meeting of the North American Network Operator's Group (NANOG 33) , Feb. 2005 . D. Dietrich. Bogons and bogon filtering. In 33rd meeting of the North American Network Operator's Group (NANOG 33), Feb. 2005."},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2004.03.033"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECCOM.2007.4550304"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1163593.1163601"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1529282.1529572"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/11909033_3"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1456441.1456445"},{"key":"e_1_2_1_19_1","volume-title":"The rise and fall of invasive ISP surveillance","author":"Ohm P.","year":"2009","unstructured":"P. Ohm . The rise and fall of invasive ISP surveillance . University of Illinois Law Review , 2009 (5). P. Ohm. The rise and fall of invasive ISP surveillance. University of Illinois Law Review, 2009(5)."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1111322.1111330"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/863955.863994"},{"key":"e_1_2_1_22_1","volume-title":"Network and Distributed System Security Symposium (NDSS)","author":"Ribeiro B.","year":"2008","unstructured":"B. Ribeiro , W. Chen , G. Miklau , and D. Towsley . Analyzing privacy in enterprise packet trace anonymization . In Network and Distributed System Security Symposium (NDSS) , 2008 . B. Ribeiro, W. Chen, G. Miklau, and D. Towsley. Analyzing privacy in enterprise packet trace anonymization. In Network and Distributed System Security Symposium (NDSS), 2008."},{"key":"e_1_2_1_23_1","volume-title":"ETH Zurich","author":"Sauter D.","year":"2009","unstructured":"D. Sauter . Invasion of Privacy Using Fingerprinting Attacks. Master Thesis MA-2008-22 , ETH Zurich , 2009 . D. Sauter. Invasion of Privacy Using Fingerprinting Attacks. Master Thesis MA-2008-22, ETH Zurich, 2009."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/1352664.1352673"},{"key":"e_1_2_1_25_1","volume-title":"FLAIM: A Multi-level Anonymization Framework for Computer and Network Logs. In USENIX Large Installation System Administration Conference (LISA)","author":"Slagell A.","year":"2006","unstructured":"A. Slagell , K. Lakkaraju , and K. Luo . FLAIM: A Multi-level Anonymization Framework for Computer and Network Logs. In USENIX Large Installation System Administration Conference (LISA) , 2006 . A. Slagell, K. Lakkaraju, and K. Luo. FLAIM: A Multi-level Anonymization Framework for Computer and Network Logs. In USENIX Large Installation System Administration Conference (LISA), 2006."},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECCMW.2005.1588299"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1142\/S0218488502001648"}],"container-title":["ACM SIGCOMM Computer Communication Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1672308.1672310","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1672308.1672310","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T20:26:24Z","timestamp":1750278384000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1672308.1672310"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010,1,7]]},"references-count":27,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2010,1,7]]}},"alternative-id":["10.1145\/1672308.1672310"],"URL":"https:\/\/doi.org\/10.1145\/1672308.1672310","relation":{},"ISSN":["0146-4833"],"issn-type":[{"value":"0146-4833","type":"print"}],"subject":[],"published":{"date-parts":[[2010,1,7]]},"assertion":[{"value":"2010-01-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}