{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T14:52:14Z","timestamp":1776783134940,"version":"3.51.2"},"reference-count":48,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"4","license":[{"start":{"date-parts":[[2017,10,1]],"date-time":"2017-10-01T00:00:00Z","timestamp":1506816000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017,10,1]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Search engine queries contain a great deal of private and potentially compromising information about users. One technique to prevent search engines from identifying the source of a query, and Internet service providers (ISPs) from identifying the contents of queries is to query the search engine over an anonymous network such as Tor.<\/jats:p><jats:p>In this paper, we study the extent to which Website Fingerprinting can be extended to fingerprint individual queries or keywords to web applications, a task we call Keyword Fingerprinting (KF). We show that by augmenting traffic analysis using a two-stage approach with new task-specific feature sets, a passive network adversary can in many cases defeat the use of Tor to protect search engine queries.<\/jats:p><jats:p>We explore three popular search engines, Google, Bing, and Duckduckgo, and several machine learning techniques with various experimental scenarios. Our experimental results show that KF can identify Google queries containing one of 300 targeted keywords with recall of 80% and precision of 91%, while identifying the specific monitored keyword among 300 search keywords with accuracy 48%. We also further investigate the factors that contribute to keyword fingerprintability to understand how search engines and users might protect against KF.<\/jats:p>","DOI":"10.1515\/popets-2017-0048","type":"journal-article","created":{"date-parts":[[2017,10,17]],"date-time":"2017-10-17T10:01:46Z","timestamp":1508234506000},"page":"251-270","source":"Crossref","is-referenced-by-count":20,"title":["Fingerprinting Keywords in Search Queries over Tor"],"prefix":"10.56553","volume":"2017","author":[{"given":"Se Eun","family":"Oh","sequence":"first","affiliation":[{"name":"University of Minnesota"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shuai","family":"Li","sequence":"additional","affiliation":[{"name":"University of Minnesota"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nicholas","family":"Hopper","sequence":"additional","affiliation":[{"name":"University of Minnesota"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"35752","published-online":{"date-parts":[[2017,10,10]]},"reference":[{"key":"2021040906175659105_j_popets-2017-0048_ref_001_w2aab3b7c13b1b6b1ab1ab1Aa","unstructured":"[1] Internet live stats. http:\/\/www.internetlivestats.com\/onesecond\/#google-band."},{"key":"2021040906175659105_j_popets-2017-0048_ref_002_w2aab3b7c13b1b6b1ab1ab2Aa","unstructured":"[2] Tor homepage. https:\/\/www.torproject.org\/."},{"key":"2021040906175659105_j_popets-2017-0048_ref_003_w2aab3b7c13b1b6b1ab1ab3Aa","unstructured":"[3] M. Backes, G. Doychev, and B. K\u00f6pf. Preventing Side-Channel Leaks in Web Traffic: A Formal Approach. NDSS, 2013."},{"key":"2021040906175659105_j_popets-2017-0048_ref_004_w2aab3b7c13b1b6b1ab1ab4Aa","doi-asserted-by":"crossref","unstructured":"[4] E. Balsa, C. Troncoso, and C. Diaz. OB-PWS: Obfuscation-based private web search. In Proceedings - IEEE Symposium on Security and Privacy, pages 491\u2013505, 2012.","DOI":"10.1109\/SP.2012.36"},{"key":"2021040906175659105_j_popets-2017-0048_ref_005_w2aab3b7c13b1b6b1ab1ab5Aa","doi-asserted-by":"crossref","unstructured":"[5] X. Cai, R. Nithyanand, and R. Johnson. Cs-buflo: A congestion sensitive website fingerprinting defense. In Proceedings of the 13th Workshop on Privacy in the Electronic Society, pages 121\u2013130. ACM, 2014.","DOI":"10.1145\/2665943.2665949"},{"key":"2021040906175659105_j_popets-2017-0048_ref_006_w2aab3b7c13b1b6b1ab1ab6Aa","doi-asserted-by":"crossref","unstructured":"[6] X. Cai, R. Nithyanand, T. Wang, R. Johnson, and I. Goldberg. A systematic approach to developing and evaluating website fingerprinting defenses. In Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201914, pages 227\u2013238, New York, NY, USA, 2014. ACM.","DOI":"10.1145\/2660267.2660362"},{"key":"2021040906175659105_j_popets-2017-0048_ref_007_w2aab3b7c13b1b6b1ab1ab7Aa","doi-asserted-by":"crossref","unstructured":"[7] X. Cai, X. Zhang, B. Joshi, and R. Johnson. Touching from a distance: Website fingerprinting attacks and defenses. Proceeding of the 2012 ACM conference on Computer and Communications Security, pages 605\u2013616, 2012.","DOI":"10.1145\/2382196.2382260"},{"key":"2021040906175659105_j_popets-2017-0048_ref_008_w2aab3b7c13b1b6b1ab1ab8Aa","doi-asserted-by":"crossref","unstructured":"[8] F. F. Chamasemani and Y. P. Singh. Multi-class Support Vector Machine (SVM) Classifiers \u2013 An Application in Hypothyroid Detection and Classification. In 2011 Sixth International Conference on Bio-Inspired Computing: Theories and Applications, pages 351\u2013356. IEEE, Sep 2011.","DOI":"10.1109\/BIC-TA.2011.51"},{"key":"2021040906175659105_j_popets-2017-0048_ref_009_w2aab3b7c13b1b6b1ab1ab9Aa","doi-asserted-by":"crossref","unstructured":"[9] C. Chang and C. Lin. LIBSVM: A library for support vector machines. ACM Transactions on Intelligent Systems and Technology, 2:27:1\u201327:27, 2011. Software available at http:\/\/www.csie.ntu.edu.tw\/~cjlin\/libsvm.","DOI":"10.1145\/1961189.1961199"},{"key":"2021040906175659105_j_popets-2017-0048_ref_010_w2aab3b7c13b1b6b1ab1ac10Aa","doi-asserted-by":"crossref","unstructured":"[10] P. Chapman and D. Evans. Automated Black-Box Detection of Side-Channel Vulnerabilities in Web Applications. Proceedings of the 18th ACM conference on Computer and communications security - CCS \u201911, (October):263, 2011.","DOI":"10.1145\/2046707.2046737"},{"key":"2021040906175659105_j_popets-2017-0048_ref_011_w2aab3b7c13b1b6b1ab1ac11Aa","doi-asserted-by":"crossref","unstructured":"[11] S. Chen, R. Wang, X. Wang, and K. Zhang. Side-channel leaks in web applications: A reality today, a challenge tomorrow. In Proceedings - IEEE Symposium on Security and Privacy, pages 191\u2013206, 2010.","DOI":"10.1109\/SP.2010.20"},{"key":"2021040906175659105_j_popets-2017-0048_ref_012_w2aab3b7c13b1b6b1ab1ac12Aa","doi-asserted-by":"crossref","unstructured":"[12] J. Domingo - Ferrer, A. Solanas, and J. Castella - Roca. h(k)\u2013private information retrieval from privacy-uncooperative queryable databases. Online Information Review, 33(4):720\u2013744, Aug 2009.10.1108\/14684520910985693","DOI":"10.1108\/14684520910985693"},{"key":"2021040906175659105_j_popets-2017-0048_ref_013_w2aab3b7c13b1b6b1ab1ac13Aa","unstructured":"[13] G. Dudek. Aol-user-ct-collection. http:\/\/www.cim.mcgill.ca\/~dudek\/206\/Logs\/AOL-user-ct-collection\/\/."},{"key":"2021040906175659105_j_popets-2017-0048_ref_014_w2aab3b7c13b1b6b1ab1ac14Aa","doi-asserted-by":"crossref","unstructured":"[14] K. P. Dyer, S. E. Coull, T. Ristenpart, and T. Shrimpton. Peek-a-boo, i still see you: Why efficient traffic analysis countermeasures fail. In Proceedings of the 2012 IEEE Symposium on Security and Privacy, SP \u201912, pages 332\u2013346, Washington, DC, USA, 2012. IEEE Computer Society.","DOI":"10.1109\/SP.2012.28"},{"key":"2021040906175659105_j_popets-2017-0048_ref_015_w2aab3b7c13b1b6b1ab1ac15Aa","doi-asserted-by":"crossref","unstructured":"[15] M. Fredrikson and B. Livshits. RePriv: Re-imagining Content Personalization and In-browser Privacy. In 2011 IEEE Symposium on Security and Privacy, pages 131\u2013146. IEEE, May 2011.","DOI":"10.1109\/SP.2011.37"},{"key":"2021040906175659105_j_popets-2017-0048_ref_016_w2aab3b7c13b1b6b1ab1ac16Aa","unstructured":"[16] Google-Instance-Disliked-Blacklist-Words. https:\/\/www.2600.com\/googleblacklist\/."},{"key":"2021040906175659105_j_popets-2017-0048_ref_017_w2aab3b7c13b1b6b1ab1ac17Aa","unstructured":"[17] G. Greenwald and E. MacAskill. NSA Prism Program Taps in to User Data of Apple, Google and Others. The Guardian, June 2013."},{"key":"2021040906175659105_j_popets-2017-0048_ref_018_w2aab3b7c13b1b6b1ab1ac18Aa","unstructured":"[18] S. Hansell. AOL Removes Search Data On Vast Group Of Web Users, 2006."},{"key":"2021040906175659105_j_popets-2017-0048_ref_019_w2aab3b7c13b1b6b1ab1ac19Aa","unstructured":"[19] J. Hayes and G. Danezis. k-fingerprinting: a Robust Scalable Website Fingerprinting Technique."},{"key":"2021040906175659105_j_popets-2017-0048_ref_020_w2aab3b7c13b1b6b1ab1ac20Aa","doi-asserted-by":"crossref","unstructured":"[20] D. Herrmann, R. Wendolsky, and H. Federrath. Website Fingerprinting: Attacking Popular Privacy Enhancing Technologies with the Multinomial Na\u00efve-Bayes Classifier. CCSW, 2009.","DOI":"10.1145\/1655008.1655013"},{"key":"2021040906175659105_j_popets-2017-0048_ref_021_w2aab3b7c13b1b6b1ab1ac21Aa","unstructured":"[21] D. C. Howe and H. Nissenbaum. TrackMeNot: Resisting Surveillance in Web Search. Lessons from the Identity Trail: Anonymity, Privacy and Identity in a Networked Society, pages 417\u2013436, 2009."},{"key":"2021040906175659105_j_popets-2017-0048_ref_022_w2aab3b7c13b1b6b1ab1ac22Aa","doi-asserted-by":"crossref","unstructured":"[22] M. Juarez, S. Afroz, G. Acar, C. Diaz, and R. Greenstadt. A Critical Evaluation of Website Fingerprinting Attacks. Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security - CCS \u201914, pages 263\u2013274, 2014.","DOI":"10.1145\/2660267.2660368"},{"key":"2021040906175659105_j_popets-2017-0048_ref_023_w2aab3b7c13b1b6b1ab1ac23Aa","doi-asserted-by":"crossref","unstructured":"[23] M. Juarez and V. Torra. DisPA: An Intelligent Agent for Private Web Search. pages 389\u2013405. Springer International Publishing, 2015.","DOI":"10.1007\/978-3-319-09885-2_21"},{"key":"2021040906175659105_j_popets-2017-0048_ref_024_w2aab3b7c13b1b6b1ab1ac24Aa","unstructured":"[24] Keyword-Tool. http:\/\/keywordtool.io."},{"key":"2021040906175659105_j_popets-2017-0048_ref_025_w2aab3b7c13b1b6b1ab1ac25Aa","doi-asserted-by":"crossref","unstructured":"[25] W. H. Kruskal and W. A. Wallis. Use of Ranks in One-Criterion Variance Analysis. Source Journal of the American Statistical Association, 4710087:583\u2013621, 1952.","DOI":"10.1080\/01621459.1952.10483441"},{"key":"2021040906175659105_j_popets-2017-0048_ref_026_w2aab3b7c13b1b6b1ab1ac26Aa","unstructured":"[26] X. Luo, P. Zhou, E. W. Chan, W. Lee, R. K. Chang, and R. Perdisci. Httpos: Sealing information leaks with browser-side obfuscation of encrypted flows. In NDSS, 2011."},{"key":"2021040906175659105_j_popets-2017-0048_ref_027_w2aab3b7c13b1b6b1ab1ac27Aa","unstructured":"[27] B. McDonald. How often does google update its search results? https:\/\/hdwebpros.com\/blog\/how-often-does-google-update-its-search-results.html, 2013."},{"key":"2021040906175659105_j_popets-2017-0048_ref_028_w2aab3b7c13b1b6b1ab1ac28Aa","unstructured":"[28] M. Miller. Google launches knowledge graph, \u2018first step in next generation search\u2019. https:\/\/searchenginewatch.com\/sew\/news\/2175783\/google-launches-knowledge-graph-step-generation-search, 2012."},{"key":"2021040906175659105_j_popets-2017-0048_ref_029_w2aab3b7c13b1b6b1ab1ac29Aa","doi-asserted-by":"crossref","unstructured":"[29] J. Ng. Blocked on Weibo: What Gets Suppressed on China\u2019s Version of Twitter (And Why). New Press, The, 2013.","DOI":"10.2307\/jj.26193073"},{"key":"2021040906175659105_j_popets-2017-0048_ref_030_w2aab3b7c13b1b6b1ab1ac30Aa","doi-asserted-by":"crossref","unstructured":"[30] A. Panchenko, F. Lanze, A. Zinnen, M. Henze, J. Pennekamp, K. Wehrle, and T. Engel. Website Fingerprinting at Internet Scale. 16th NDSS (NDSS 16), pages 143\u2013157, 2016.","DOI":"10.14722\/ndss.2016.23477"},{"key":"2021040906175659105_j_popets-2017-0048_ref_031_w2aab3b7c13b1b6b1ab1ac31Aa","doi-asserted-by":"crossref","unstructured":"[31] A. Panchenko, L. Niessen, A. Zinnen, and T. Engel. Website Fingerprinting in Onion Routing Based Anonymization Networks. WPES, 2011.","DOI":"10.1145\/2046556.2046570"},{"key":"2021040906175659105_j_popets-2017-0048_ref_032_w2aab3b7c13b1b6b1ab1ac32Aa","unstructured":"[32] M. Perry. Experimental defense for website traffic fingerprinting. https:\/\/blog.torproject.org\/blog\/experimental-defense-website-traffic-fingerprinting, 2011. Accessed: 2015-11-23."},{"key":"2021040906175659105_j_popets-2017-0048_ref_033_w2aab3b7c13b1b6b1ab1ac33Aa","unstructured":"[33] M. Perry. A critique of website traffic fingerprinting attacks. https:\/\/blog.torproject.org\/blog\/critique-website-traffic-fingerprinting-attacks, 2013. Accessed: 2015-11-1."},{"key":"2021040906175659105_j_popets-2017-0048_ref_034_w2aab3b7c13b1b6b1ab1ac34Aa","doi-asserted-by":"crossref","unstructured":"[34] A. Schaub, E. Schneider, A. Hollender, V. Calasans, L. Jolie, R. Touillon, A. Heuser, S. Guilley, and O. Rioul. Attacking Suggest Boxes in Web Applications Over HTTPS Using Side-Channel Stochastic Algorithms. Risks and Security of Internet and Systems, 2015.","DOI":"10.1007\/978-3-319-17127-2_8"},{"key":"2021040906175659105_j_popets-2017-0048_ref_035_w2aab3b7c13b1b6b1ab1ac35Aa","doi-asserted-by":"crossref","unstructured":"[35] S. A. Sharma and B. L. Menezes. Implementing side-channel attacks on suggest boxes in web applications. In Proceedings of the First International Conference on Security of Internet of Things - SecurIT \u201912, pages 57\u201362, New York, New York, USA, 2012. ACM Press.","DOI":"10.1145\/2490428.2490436"},{"key":"2021040906175659105_j_popets-2017-0048_ref_036_w2aab3b7c13b1b6b1ab1ac36Aa","unstructured":"[36] J. Slegg. Google adds \u201cpeople also search for\u201d thumbnails to search results. http:\/\/www.thesempost.com\/google-adds-people-also-search-for-thumbnails-to-search-results\/, 2016."},{"key":"2021040906175659105_j_popets-2017-0048_ref_037_w2aab3b7c13b1b6b1ab1ac37Aa","unstructured":"[37] A. Smarty. Google\u2019s \u201cpeople also ask\u201d (related questions): What are they, and why you should care. http:\/\/www.internetmarketingninjas.com\/blog\/search-engine-optimization\/googles-people-also-ask-related-questions\/, 2016."},{"key":"2021040906175659105_j_popets-2017-0048_ref_038_w2aab3b7c13b1b6b1ab1ac38Aa","unstructured":"[38] J. Titanium. AOL Search Log Special, Part 1. http:\/\/www.somethingawful.com\/weekend-web\/aol-search-log\/, 2006."},{"key":"2021040906175659105_j_popets-2017-0048_ref_039_w2aab3b7c13b1b6b1ab1ac39Aa","unstructured":"[39] Tor-Browser-Crawler. https:\/\/github.com\/webfp\/tor-browser-crawler."},{"key":"2021040906175659105_j_popets-2017-0048_ref_040_w2aab3b7c13b1b6b1ab1ac40Aa","unstructured":"[40] tshark. https:\/\/www.wireshark.org\/docs\/manpages\/tshark.html."},{"key":"2021040906175659105_j_popets-2017-0048_ref_041_w2aab3b7c13b1b6b1ab1ac41Aa","unstructured":"[41] D. Wagner, B. Schneier, et al. Analysis of the ssl 3.0 protocol. In The Second USENIX Workshop on Electronic Commerce Proceedings, pages 29\u201340, 1996."},{"key":"2021040906175659105_j_popets-2017-0048_ref_042_w2aab3b7c13b1b6b1ab1ac42Aa","doi-asserted-by":"crossref","unstructured":"[42] L. Wang, K. P. Dyer, A. Akella, T. Ristenpart, and T. Shrimpton. Seeing through Network-Protocol Obfuscation. Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pages 57\u201369, 2015.","DOI":"10.1145\/2810103.2813715"},{"key":"2021040906175659105_j_popets-2017-0048_ref_043_w2aab3b7c13b1b6b1ab1ac43Aa","unstructured":"[43] T. Wang, X. Cai, R. Nithyanand, R. Johnson, and I. Goldberg. Effective Attacks and Provable Defenses for Website Fingerprinting. 23rd USENIX Security Symposium (USENIX Security 14), pages 143\u2013157, 2014."},{"key":"2021040906175659105_j_popets-2017-0048_ref_044_w2aab3b7c13b1b6b1ab1ac44Aa","doi-asserted-by":"crossref","unstructured":"[44] T. Wang and I. Goldberg. Improved website fingerprinting on Tor. Proceedings of the 12th ACM workshop on Workshop on privacy in the electronic society - WPES \u201913, pages 201\u2013212, 2013.","DOI":"10.1145\/2517840.2517851"},{"key":"2021040906175659105_j_popets-2017-0048_ref_045_w2aab3b7c13b1b6b1ab1ac45Aa","doi-asserted-by":"crossref","unstructured":"[45] T. Wang and I. Goldberg. On Realistically Attacking Tor with Website Fingerprinting. Proceedings on Privacy Enhancing Technologies, (4):21\u201336, 2016.","DOI":"10.1515\/popets-2016-0027"},{"key":"2021040906175659105_j_popets-2017-0048_ref_046_w2aab3b7c13b1b6b1ab1ac46Aa","unstructured":"[46] T. Wang and I. Goldberg. Walkie-Talkie: An Efficient Defense Against Passive Website Fingerprinting Attacks. 26th USENIX Security Symposium (USENIX Security 17), 2017."},{"key":"2021040906175659105_j_popets-2017-0048_ref_047_w2aab3b7c13b1b6b1ab1ac47Aa","unstructured":"[47] C. V. Wright, S. E. Coull, and F. Monrose. Traffic morphing: An efficient defense against statistical traffic analysis. In NDSS, 2009."},{"key":"2021040906175659105_j_popets-2017-0048_ref_048_w2aab3b7c13b1b6b1ab1ac48Aa","doi-asserted-by":"crossref","unstructured":"[48] K. Zhang, Z. Li, R. Wang, X. F. Wang, and S. Chen. Sidebuster: Automated detection and quantification of side-channel leaks in web application development. In Proceedings of the ACM Conference on Computer and Communications Security, pages 595\u2013606, 2010.","DOI":"10.1145\/1866307.1866374"}],"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/content.sciendo.com\/view\/journals\/popets\/2017\/4\/article-p251.xml","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.sciendo.com\/article\/10.1515\/popets-2017-0048","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,26]],"date-time":"2025-06-26T14:51:06Z","timestamp":1750949466000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2017\/popets-2017-0048.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,10,1]]},"references-count":48,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2017,10,10]]},"published-print":{"date-parts":[[2017,10,1]]}},"alternative-id":["10.1515\/popets-2017-0048"],"URL":"https:\/\/doi.org\/10.1515\/popets-2017-0048","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,10,1]]}}}