{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T18:09:51Z","timestamp":1775066991305,"version":"3.50.1"},"reference-count":113,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"4","license":[{"start":{"date-parts":[[2021,7,23]],"date-time":"2021-07-23T00:00:00Z","timestamp":1626998400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,10,1]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Although the security benefits of domain name encryption technologies such as DNS over TLS (DoT), DNS over HTTPS (DoH), and Encrypted Client Hello (ECH) are clear, their positive impact on user privacy is weakened by\u2014the still exposed\u2014IP address information. However, content delivery networks, DNS-based load balancing, co-hosting of different websites on the same server, and IP address churn, all contribute towards making domain\u2013IP mappings unstable, and prevent straightforward IP-based browsing tracking.<\/jats:p><jats:p>In this paper, we show that this instability is not a roadblock (assuming a universal DoT\/DoH and ECH deployment), by introducing an IP-based website finger-printing technique that allows a network-level observer to identify<jats:italic>at scale<\/jats:italic>the website a user visits. Our technique exploits the complex structure of most websites, which load resources from several domains besides their primary one. Using the generated fingerprints of more than 200K websites studied, we could successfully identify 84% of them when observing solely destination IP addresses. The accuracy rate increases to 92% for popular websites, and 95% for popular<jats:italic>and<\/jats:italic>sensitive web-sites. We also evaluated the robustness of the generated fingerprints over time, and demonstrate that they are still effective at successfully identifying about 70% of the tested websites after two months. We conclude by discussing strategies for website owners and hosting providers towards hindering IP-based website fingerprinting and maximizing the privacy benefits offered by DoT\/DoH and ECH.<\/jats:p>","DOI":"10.2478\/popets-2021-0078","type":"journal-article","created":{"date-parts":[[2021,7,24]],"date-time":"2021-07-24T23:23:58Z","timestamp":1627169038000},"page":"420-440","source":"Crossref","is-referenced-by-count":17,"title":["Domain name encryption is not enough: privacy leakage via IP-based website fingerprinting"],"prefix":"10.56553","volume":"2021","author":[{"given":"Nguyen Phong","family":"Hoang","sequence":"first","affiliation":[{"name":"Stony Brook University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Arian Akhavan","family":"Niaki","sequence":"additional","affiliation":[{"name":"University of Massachusetts -Amherst"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Phillipa","family":"Gill","sequence":"additional","affiliation":[{"name":"University of Massachusetts - Amherst"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michalis","family":"Polychronakis","sequence":"additional","affiliation":[{"name":"Stony Brook University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"35752","published-online":{"date-parts":[[2021,7,23]]},"reference":[{"key":"2022051409232290042_j_popets-2021-0078_ref_001","unstructured":"[1] Pre-alpha: Run an Onion Proxy Now! https:\/\/lists.torproject.org\/pipermail\/tor-dev\/2002-September\/002374.html."},{"key":"2022051409232290042_j_popets-2021-0078_ref_002","unstructured":"[2] Cisco IOS NetFlow. http:\/\/bit.ly\/CiscoNetFlow, 2012."},{"key":"2022051409232290042_j_popets-2021-0078_ref_003","unstructured":"[3] Encrypt the Web. https:\/\/eff.org\/encrypt-the-web, 2019."},{"key":"2022051409232290042_j_popets-2021-0078_ref_004","unstructured":"[4] Cloudflare DoH. http:\/\/bit.ly\/CloudflareDoH, 2020."},{"key":"2022051409232290042_j_popets-2021-0078_ref_005","unstructured":"[5] Quantcast. https:\/\/www.quantcast.com\/top-sites\/, 2020."},{"key":"2022051409232290042_j_popets-2021-0078_ref_006","unstructured":"[6] Stat Counter: Browser Market Share Worldwide. https:\/\/gs.statcounter.com\/browser-market-share, 2020."},{"key":"2022051409232290042_j_popets-2021-0078_ref_007","unstructured":"[7] State of the Web. https:\/\/httparchive.org\/reports\/state-ofthe-web, 2020."},{"key":"2022051409232290042_j_popets-2021-0078_ref_008","unstructured":"[8] Verisign report - the domain name industry brief. https:\/\/bit.ly\/Verisign-Report, 2020."},{"key":"2022051409232290042_j_popets-2021-0078_ref_009","unstructured":"[9] Alexa Top Sites. https:\/\/www.alexa.com\/, 2021."},{"key":"2022051409232290042_j_popets-2021-0078_ref_010","unstructured":"[10] IP Feeds by FireHOL. https:\/\/iplists.firehol.org\/, 2021."},{"key":"2022051409232290042_j_popets-2021-0078_ref_011","unstructured":"[11] The Majestic Million. http:\/\/bit.ly\/MajesticList, 2021."},{"key":"2022051409232290042_j_popets-2021-0078_ref_012","unstructured":"[12] Umbrella popularity list. http:\/\/bit.ly\/UmbrellaList, 2021."},{"key":"2022051409232290042_j_popets-2021-0078_ref_013","doi-asserted-by":"crossref","unstructured":"[13] Azadeh Akbari and Rashid Gabdulhakov. Platform Surveil-lance and Resistance in Iran and Russia : The Case of Telegram. In Surveillance and Society, 2019.10.24908\/ss.v17i1\/2.12928","DOI":"10.24908\/ss.v17i1\/2.12928"},{"key":"2022051409232290042_j_popets-2021-0078_ref_014","unstructured":"[14] Anonymous, AA. Niaki, NP. Hoang, P. Gill, and A. Houmansadr. Triplet censors: Demystifying great fire-wall\u2019s DNS censorship behavior. In USENIX FOCI \u201920."},{"key":"2022051409232290042_j_popets-2021-0078_ref_015","doi-asserted-by":"crossref","unstructured":"[15] Ricardo Baeza-Yates, Carlos Castillo, and Felipe Saint-Jean. Web Dynamics, Structure, and Page Quality. 2004.10.1007\/978-3-662-10874-1_5","DOI":"10.1007\/978-3-662-10874-1_5"},{"key":"2022051409232290042_j_popets-2021-0078_ref_016","unstructured":"[16] Robert Beverly. A Robust Classifier for Passive TCP\/IP Fingerprinting. In PAM \u201904."},{"key":"2022051409232290042_j_popets-2021-0078_ref_017","doi-asserted-by":"crossref","unstructured":"[17] Simon Blake-Wilson, Magnus Nystrom, David Hopwood, Jan Mikkelsen, and Tim Wright. Transport Layer Security (TLS) Extensions. RFC 3546, IETF, June 2003.10.17487\/rfc3546","DOI":"10.17487\/rfc3546"},{"key":"2022051409232290042_j_popets-2021-0078_ref_018","unstructured":"[18] Thomas Brewster. Now Those Privacy Rules Are Gone, This Is How ISPs Will Actually Sell Your Personal Data. https:\/\/bit.ly\/Forbes-ISP-sells-data, 2017."},{"key":"2022051409232290042_j_popets-2021-0078_ref_019","unstructured":"[19] J. Bushart and C. Rossow. Padding ain\u2019t enough: Assessing the privacy guarantees of encrypted DNS. In FOCI \u201920."},{"key":"2022051409232290042_j_popets-2021-0078_ref_020","unstructured":"[20] X. Cai, R. Nithyanand, T. Wang, R. Johnson, and I. Goldberg. A Systematic Approach to Developing and Evaluating Website Fingerprinting Defenses. In ACM CCS \u201914."},{"key":"2022051409232290042_j_popets-2021-0078_ref_021","unstructured":"[21] Frank Cangialosi, Taejoong Chung, David Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, and Christo Wilson. Measurement and analysis of private key sharing in the https:\/\/ecosystem. In ACM CCS \u201916."},{"key":"2022051409232290042_j_popets-2021-0078_ref_022","doi-asserted-by":"crossref","unstructured":"[22] Giovanni Cherubin, Jamie Hayes, and Marc Juarez. Website Fingerprinting Defenses at the Application Layer. 2017.10.1515\/popets-2017-0023","DOI":"10.1515\/popets-2017-0023"},{"key":"2022051409232290042_j_popets-2021-0078_ref_023","unstructured":"[23] S. Coull, M. Collins, C. Wright, F. Monrose, and M. Reiter. On web browsing privacy in anonymized netflows. In USENIX Security \u201907."},{"key":"2022051409232290042_j_popets-2021-0078_ref_024","unstructured":"[24] W. Cui, T. Chen, C. Fields, J. Chen, A. Sierra, and E. Chan-Tin. Revisiting assumptions for website finger-printing attacks. In ACM AsiaCCS \u201919."},{"key":"2022051409232290042_j_popets-2021-0078_ref_025","unstructured":"[25] Casey Deccio and Jacob Davis. DNS Privacy in Practice and Preparation. In ACM CoNEXT \u201919."},{"key":"2022051409232290042_j_popets-2021-0078_ref_026","unstructured":"[26] R. Dingledine, N. Mathewson, and P. Syverson. Tor: The Second-Generation Onion Router. In USENIX Security \u201904."},{"key":"2022051409232290042_j_popets-2021-0078_ref_027","unstructured":"[27] H. Duan, N. Weaver, Z. Zhao, M. Hu, J. Liang, J. Jiang, K. Li, and V. Paxson. Hold-On: Protecting Against On-Path DNS Poisoning. In SATIN \u201912."},{"key":"2022051409232290042_j_popets-2021-0078_ref_028","unstructured":"[28] AP. Felt, R. Barnes, A. King, C. Palmer, C. Bentzel, and P. Tabriz. Measuring HTTPS Adoption on the Web. In USENIX Security \u201917."},{"key":"2022051409232290042_j_popets-2021-0078_ref_029","unstructured":"[29] R. Fielding, J. Gettys, J. Mogul, H. Frystyk, L. Masinter, P. Leach, and T. Berners-Lee. HTTP\/1.1. RFC 2616, June 1999."},{"key":"2022051409232290042_j_popets-2021-0078_ref_030","unstructured":"[30] Edward W. Forgy. Cluster Analysis of Multivariate Data : Efficiency Versus Interpretability of Classifications. 1965."},{"key":"2022051409232290042_j_popets-2021-0078_ref_031","unstructured":"[31] Christian Fuchs, Kees Boersma, Anders Albrechtslund, and Marisol Sandoval. Internet and Surveillance: The Challenges of Web 2.0 and Social Media. 2011."},{"key":"2022051409232290042_j_popets-2021-0078_ref_032","doi-asserted-by":"crossref","unstructured":"[32] I. Goldberg, D. Wagner, and E. Brewer. Privacy-Enhancing Technologies for the Internet. In Proceedings of the 42nd IEEE International Computer Conference, 1997.10.21236\/ADA385546","DOI":"10.21236\/ADA385546"},{"key":"2022051409232290042_j_popets-2021-0078_ref_033","unstructured":"[33] J. Gong and T. Wang. Zero-delay Lightweight Defenses against Website Fingerprinting. In USENIX Security \u201920\u2019."},{"key":"2022051409232290042_j_popets-2021-0078_ref_034","unstructured":"[34] R. Gonzalez, Claudio Soriente, and Nikolaos Laoutaris. User profiling in the time of https. In ACM IMC \u201916."},{"key":"2022051409232290042_j_popets-2021-0078_ref_035","unstructured":"[35] Google. JSON API for DNS over HTTPS (DoH). https:\/\/developers.google.com\/speed\/public-dns\/docs\/dns-over-https, 2019."},{"key":"2022051409232290042_j_popets-2021-0078_ref_036","unstructured":"[36] Google Developers. Remove Render-Blocking JavaScript. https:\/\/developers.google.com\/speed\/docs\/insights\/BlockingJS, 2018."},{"key":"2022051409232290042_j_popets-2021-0078_ref_037","unstructured":"[37] B. Greschbach, T. Pulls, LM. Roberts, P. Winter, and N. Feamster. The Effect of DNS on Tor\u2019s Anonymity. In NDSS \u201917."},{"key":"2022051409232290042_j_popets-2021-0078_ref_038","unstructured":"[38] Ilya Grigorik. Critical Rendering Path. http:\/\/bit.ly\/CriticalRenderingPath, 2018."},{"key":"2022051409232290042_j_popets-2021-0078_ref_039","unstructured":"[39] B. Haas. Man in China Sentenced to Five years\u2019 Jail for Running VPN. https:\/\/www.theguardian.com\/world\/2017\/dec\/22\/man-in-china-sentenced-to-five-years-jail-for-running-vpn."},{"key":"2022051409232290042_j_popets-2021-0078_ref_040","unstructured":"[40] J. Hayes and G. Danezis. k-fingerprinting: A Robust Scalable Website Fingerprinting Technique. In USENIX Security Symposium 2016."},{"key":"2022051409232290042_j_popets-2021-0078_ref_041","doi-asserted-by":"crossref","unstructured":"[41] A. Hintz. Fingerprinting Websites Using Traffic Analysis. In Conference on Privacy Enhancing Technologies, 2002.10.1007\/3-540-36467-6_13","DOI":"10.1007\/3-540-36467-6_13"},{"key":"2022051409232290042_j_popets-2021-0078_ref_042","doi-asserted-by":"crossref","unstructured":"[42] NP. Hoang, Y. Asano, and M. Yoshikawa. Your Neighbors Are My Spies: Location and other Privacy Concerns in GLBT-focused Location-based Dating Applications. In Trans. on Advanced Communications Technology 2016.10.1109\/ICACT.2016.7423531","DOI":"10.1109\/ICACT.2016.7423531"},{"key":"2022051409232290042_j_popets-2021-0078_ref_043","unstructured":"[43] NP. Hoang, P. Kintis, M. Antonakakis, and M. Polychronakis. An Empirical Study of the I2P Anonymity Network and Its Censorship Resistance. In ACM IMC \u201918."},{"key":"2022051409232290042_j_popets-2021-0078_ref_044","unstructured":"[44] NP. Hoang, I. Lin, S. Ghavamnia, and M. Polychronakis. K-resolver: Towards Decentralizing Encrypted DNS Resolution. In MADWeb \u201920."},{"key":"2022051409232290042_j_popets-2021-0078_ref_045","unstructured":"[45] NP. Hoang, AA. Niaki, N. Borisov, P. Gill, and M. Polychronakis. Assessing the Privacy Benefits of Domain Name Encryption. In ACM AsiaCCS \u201920."},{"key":"2022051409232290042_j_popets-2021-0078_ref_046","unstructured":"[46] NP. Hoang, AA. Niaki, J. Dalek, J. Knockel, P. Lin, B. Marczak, M. Crete-Nishihata, P. Gill, and M. Polychronakis. How Great is the Great Firewall? Measuring China\u2019s DNS Censorship. In USENIX Security \u201921."},{"key":"2022051409232290042_j_popets-2021-0078_ref_047","doi-asserted-by":"crossref","unstructured":"[47] NP. Hoang, AA. Niaki, M. Polychronakis, and P. Gill. The Web is Still Small After More Than a Decade. ACM SIGCOMM Computer Communication Review 2020.10.1145\/3402413.3402417","DOI":"10.1145\/3402413.3402417"},{"key":"2022051409232290042_j_popets-2021-0078_ref_048","unstructured":"[48] NP. Hoang and D. Pishva. Anonymous Communication and Its Importance in Social Networking. In ICACT \u201914."},{"key":"2022051409232290042_j_popets-2021-0078_ref_049","doi-asserted-by":"crossref","unstructured":"[49] P. Hoffman and P. McManus. DNS queries over HTTPS. RFC 8484, IETF, October 2018.10.17487\/RFC8484","DOI":"10.17487\/RFC8484"},{"key":"2022051409232290042_j_popets-2021-0078_ref_050","doi-asserted-by":"crossref","unstructured":"[50] Rebekah Houser, Zhou Li, Chase Cotton, and Haining Wang. An Investigation on Information Leakage of DNS over TLS. In ACM CoNEXT, 2019.10.1145\/3359989.3365429","DOI":"10.1145\/3359989.3365429"},{"key":"2022051409232290042_j_popets-2021-0078_ref_051","doi-asserted-by":"crossref","unstructured":"[51] Z. Hu, L. Zhu, J. Heidemann, A. Mankin, D. Wessels, and P. Hoffman. Specification for DNS over transport layer security (TLS). RFC 7858, IETF, May 2016.10.17487\/RFC7858","DOI":"10.17487\/RFC7858"},{"key":"2022051409232290042_j_popets-2021-0078_ref_052","unstructured":"[52] Kevin Jacobs. Encrypted Client Hello: the future of ESNI in Firefox. http:\/\/blog.mozilla.org\/security\/2021\/01\/07\/encrypted-client-hello-the-future-of-esni-in-firefox, 2021."},{"key":"2022051409232290042_j_popets-2021-0078_ref_053","doi-asserted-by":"crossref","unstructured":"[53] Marc Juarez, Sadia Afroz, Gunes Acar, Claudia Diaz, and Rachel Greenstadt. A Critical Evaluation of Website Fingerprinting Attacks. In ACM CCS, 2014.10.1145\/2660267.2660368","DOI":"10.1145\/2660267.2660368"},{"key":"2022051409232290042_j_popets-2021-0078_ref_054","doi-asserted-by":"crossref","unstructured":"[54] Marc Juarez, Mohsen Imani, Mike Perry, Claudia Diaz, and Matthew Wright. Toward an efficient website fingerprinting defense. In ESORICS, 2016.10.1007\/978-3-319-45744-4_2","DOI":"10.1007\/978-3-319-45744-4_2"},{"key":"2022051409232290042_j_popets-2021-0078_ref_055","unstructured":"[55] Sarah Krouse and Patience Haggin. Internet Providers Look to Cash In on Your Web Habits. https:\/\/www.wsj.com\/articles\/facebook-knows-a-lot-about-you-so-does-your-internet-provider-11561627803, 2019."},{"key":"2022051409232290042_j_popets-2021-0078_ref_056","doi-asserted-by":"crossref","unstructured":"[56] Douglas J. Leith. Web browser privacy: What do browsers say when they phone home? 2020.10.1109\/ACCESS.2021.3065243","DOI":"10.1109\/ACCESS.2021.3065243"},{"key":"2022051409232290042_j_popets-2021-0078_ref_057","doi-asserted-by":"crossref","unstructured":"[57] Mark Levene. Web dynamics: Adapting to change in content, size, topology and use. Springer Science & Business Media, 2004.","DOI":"10.1007\/978-3-662-10874-1"},{"key":"2022051409232290042_j_popets-2021-0078_ref_058","doi-asserted-by":"crossref","unstructured":"[58] M. Liberatore and BN. Levine. Inferring the Source of Encrypted HTTP Connections. In ACM CCS \u201906, 2006.10.1145\/1180405.1180437","DOI":"10.1145\/1180405.1180437"},{"key":"2022051409232290042_j_popets-2021-0078_ref_059","doi-asserted-by":"crossref","unstructured":"[59] T. Libert and R. Binns. Good news for people who love bad news: Centralization, privacy, and transparency on us news sites. ACM Conference on Web Science, 2019.10.1145\/3292522.3326019","DOI":"10.1145\/3292522.3326019"},{"key":"2022051409232290042_j_popets-2021-0078_ref_060","doi-asserted-by":"crossref","unstructured":"[60] Stuart P. Lloyd. Least squares quantization in pcm. 1982.10.1109\/TIT.1982.1056489","DOI":"10.1109\/TIT.1982.1056489"},{"key":"2022051409232290042_j_popets-2021-0078_ref_061","unstructured":"[61] Chaoyi Lu, Baojun Liu, Zhou Li, Shuang Hao, Haixin Duan, Mingming Zhang, Chunying Leng, Ying Liu, Zaifeng Zhang, and Jianping Wu. An End-to-End, Large-Scale Measurement of DNS-over-Encryption: How Far Have We Come? In ACM Internet Measurement Conference, 2019."},{"key":"2022051409232290042_j_popets-2021-0078_ref_062","unstructured":"[62] X. Luo, P. Zhou, E. Chan, W. Lee, R. Chang, and R. Perdisci. HTTPOS: Sealing Information Leaks with Browser-side Obfuscation of Encrypted Flows. In Network and Distributed System Security Symposium, 2011."},{"key":"2022051409232290042_j_popets-2021-0078_ref_063","unstructured":"[63] James B. MacQueen. Some methods for classification and analysis of multivariate observations. 1967."},{"key":"2022051409232290042_j_popets-2021-0078_ref_064","unstructured":"[64] M. Di Martino, P. Quax, and W. Lamotte. Realistically Fingerprinting Social Media Webpages in HTTPS Traffic. In ACM ARES \u201919."},{"key":"2022051409232290042_j_popets-2021-0078_ref_065","doi-asserted-by":"crossref","unstructured":"[65] Mariano Di Martino, P. Quax, and W. Lamotte. Knocking on IPs: Identifying HTTPS Websites for Zero-Rated Traffic. Security and Communication Networks 2020.10.1155\/2020\/7285786","DOI":"10.1155\/2020\/7285786"},{"key":"2022051409232290042_j_popets-2021-0078_ref_066","unstructured":"[66] A. Mayrhofer. Padding Policies for EDNS(0). RFC 8467, IETF, 2018."},{"key":"2022051409232290042_j_popets-2021-0078_ref_067","unstructured":"[67] Patrick McManus. Improving DNS privacy in firefox. https:\/\/blog.nightly.mozilla.org\/2018\/06\/01\/improving-dns-privacy-in-firefox\/, 2018."},{"key":"2022051409232290042_j_popets-2021-0078_ref_068","unstructured":"[68] MDN Web Docs. Domain sharding. https:\/\/developer.mozilla.org\/en-US\/docs\/Glossary\/Domain_sharding, 2020."},{"key":"2022051409232290042_j_popets-2021-0078_ref_069","unstructured":"[69] MDN Web Docs. DOMContentLoaded event. https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/Window\/DOMContentLoaded_event, 2020."},{"key":"2022051409232290042_j_popets-2021-0078_ref_070","doi-asserted-by":"crossref","unstructured":"[70] Brad Miller, Ling Huang, Anthony D. Joseph, and J. Doug Tygar. I Know Why You Went to the Clinic: Risks and Realization of HTTPS Traffic Analysis. In Privacy Enhancing Technologies Symposium, 2014.10.1007\/978-3-319-08506-7_8","DOI":"10.1007\/978-3-319-08506-7_8"},{"key":"2022051409232290042_j_popets-2021-0078_ref_071","unstructured":"[71] Alec Muffett. No Port 53, Who Dis? A year of DNS over HTTPS over Tor. In DNS Privacy Workshop 2021."},{"key":"2022051409232290042_j_popets-2021-0078_ref_072","unstructured":"[72] Rayan Naqash. India\u2019s crackdown on VPNs in Kashmir seeks to quell cyber-insurgency threat but risks blowback. hhttps:\/\/bit.ly\/India-blocks-VPN, 2020."},{"key":"2022051409232290042_j_popets-2021-0078_ref_073","doi-asserted-by":"crossref","unstructured":"[73] Milad Nasr, Alireza Bahramali, and Amir Houmansadr. DeepCorr: Strong Flow Correlation Attacks on Tor Using Deep Learning. In ACM CCS, 2018.10.1145\/3243734.3243824","DOI":"10.1145\/3243734.3243824"},{"key":"2022051409232290042_j_popets-2021-0078_ref_074","unstructured":"[74] Milad Nasr, Amir Houmansadr, and A. Mazumdar. Compressive traffic analysis: A new paradigm for scalable traffic analysis. In ACM CCS \u201917."},{"key":"2022051409232290042_j_popets-2021-0078_ref_075","unstructured":"[75] Arian Akhavan Niaki, Shinyoung Cho, Zachary Weinberg, Nguyen Phong Hoang, Abbas Razaghpanah, Nicolas Christin, and Phillipa Gill. ICLab: A Global, Longitudinal Internet Censorship Measurement Platform. In Symposium on Security and Privacy, May 2020."},{"key":"2022051409232290042_j_popets-2021-0078_ref_076","doi-asserted-by":"crossref","unstructured":"[76] Nick Nikiforakis, Luca Invernizzi, Alexandros Kapravelos, Steven Van Acker, Wouter Joosen, Christopher Kruegel, Frank Piessens, and Giovanni Vigna. You are what you include: Large-scale evaluation of remote javascript inclusions. In ACM Conference on Computer and Communications Security, 2012.10.1145\/2382196.2382274","DOI":"10.1145\/2382196.2382274"},{"key":"2022051409232290042_j_popets-2021-0078_ref_077","doi-asserted-by":"crossref","unstructured":"[77] Rishab Nithyanand, Xiang Cai, and Rob Johnson. Glove: A bespoke website fingerprinting defense. In WPES, 2014.10.1145\/2665943.2665950","DOI":"10.1145\/2665943.2665950"},{"key":"2022051409232290042_j_popets-2021-0078_ref_078","unstructured":"[78] NP. Hoang and S. Doreen and M. Polychronakis. Measuring I2P Censorship at a Global Scale. In FOCI \u201919."},{"key":"2022051409232290042_j_popets-2021-0078_ref_079","doi-asserted-by":"crossref","unstructured":"[79] Andriy Panchenko, Fabian Lanze, Jan Pennekamp, Thomas Engel, Andreas Zinnen, Martin Henze, and Klaus Wehrle. Website fingerprinting at internet scale. In Network and Distributed System Security Symposium, 2016.10.14722\/ndss.2016.23477","DOI":"10.14722\/ndss.2016.23477"},{"key":"2022051409232290042_j_popets-2021-0078_ref_080","doi-asserted-by":"crossref","unstructured":"[80] Andriy Panchenko, Lukas Niessen, Andreas Zinnen, and Thomas Engel. Website fingerprinting in onion routing based anonymization networks. In WPES, 2011.10.1145\/2046556.2046570","DOI":"10.1145\/2046556.2046570"},{"key":"2022051409232290042_j_popets-2021-0078_ref_081","doi-asserted-by":"crossref","unstructured":"[81] S. Patil and N. Borisov. What Can You Learn from an IP? In Applied Networking Research Workshop, 2019.10.1145\/3340301.3341133","DOI":"10.1145\/3340301.3341133"},{"key":"2022051409232290042_j_popets-2021-0078_ref_082","unstructured":"[82] Paul Pearce, Ben Jones, Frank Li, Roya Ensafi, Nick Feamster, Nick Weaver, and Vern Paxson. Global Measurement of DNS Manipulation. In USENIX Security \u201917, 2017."},{"key":"2022051409232290042_j_popets-2021-0078_ref_083","unstructured":"[83] Mike Perry. A Critique of Website Traffic Fingerprinting Attacks, 2013. https:\/\/blog.torproject.org\/critique-websitetraffic-fingerprinting-attacks."},{"key":"2022051409232290042_j_popets-2021-0078_ref_084","unstructured":"[84] Victor Le Pochat, Tom Van Goethem, and Wouter Joosen. Evaluating the long-term effects of parameters on the characteristics of the tranco top sites ranking. In USENIX Workshop on Cyber Security Experimentation and Test, 2019."},{"key":"2022051409232290042_j_popets-2021-0078_ref_085","doi-asserted-by":"crossref","unstructured":"[85] Tobias Pulls and Rasmus Dahlberg. Website fingerprinting with website oracles. PETS, 2020.10.2478\/popets-2020-0013","DOI":"10.2478\/popets-2020-0013"},{"key":"2022051409232290042_j_popets-2021-0078_ref_086","doi-asserted-by":"crossref","unstructured":"[86] Abbas Razaghpanah, Rishab Nithyanand, Narseo Vallina-Rodriguez, Srikanth Sundaresan, Mark Allman, Christian Kreibich, and Phillipa Gill. Apps, trackers, privacy, and regulators: A global study of the mobile tracking ecosystem. In Network and Distributed System Security Symposium, 2018.10.14722\/ndss.2018.23353","DOI":"10.14722\/ndss.2018.23353"},{"key":"2022051409232290042_j_popets-2021-0078_ref_087","unstructured":"[87] E. Rescorla, K. Oku, N. Sullivan, and C. Wood. ESNI for TLS 1.3. Internet draft, IETF, March 2020."},{"key":"2022051409232290042_j_popets-2021-0078_ref_088","unstructured":"[88] E. Rescorla, K. Oku, N. Sullivan, and C. Wood. TLS Encrypted Client Hello. Internet draft, IETF, June 2020."},{"key":"2022051409232290042_j_popets-2021-0078_ref_089","doi-asserted-by":"crossref","unstructured":"[89] Walter Rweyemamu, Christo Lauinger, Tobiasand Wilson, William Robertson, and Engin Kirda. Clustering and the Weekend Effect: Recommendations for the Use of Top Domain Lists in Security Research. In PAM, 2019.10.1007\/978-3-030-15986-3_11","DOI":"10.1007\/978-3-030-15986-3_11"},{"key":"2022051409232290042_j_popets-2021-0078_ref_090","doi-asserted-by":"crossref","unstructured":"[90] S. Santesson, M. Myers, R. Ankney, A. Malpani, S. Galperin, and C. Adams. X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP. RFC 6960, IETF, June 2013.10.17487\/rfc6960","DOI":"10.17487\/rfc6960"},{"key":"2022051409232290042_j_popets-2021-0078_ref_091","unstructured":"[91] Mahrud Sayrafi. Introducing DNS resolver for Tor. https:\/\/blog.cloudflare.com\/welcome-hidden-resolver\/, 2018."},{"key":"2022051409232290042_j_popets-2021-0078_ref_092","doi-asserted-by":"crossref","unstructured":"[92] Paul Schmitt, Anne Edmundson, Allison Mankin, and Nick Feamster. Oblivious DNS: Practical Privacy for DNS Queries. In PETS, 2019.10.1145\/3340301.3341128","DOI":"10.1145\/3340301.3341128"},{"key":"2022051409232290042_j_popets-2021-0078_ref_093","doi-asserted-by":"crossref","unstructured":"[93] Zain Shamsi, Ankur Nandwani, D. Leonard, and D. Loguinov. Hershel: Single-packet os fingerprinting. IEEE\/ACM Transactions on Networking, 24:2196\u20132209, 2016.","DOI":"10.1109\/TNET.2015.2447492"},{"key":"2022051409232290042_j_popets-2021-0078_ref_094","doi-asserted-by":"crossref","unstructured":"[94] C. E. Shannon. A mathematical theory of communication. SIGMOBILE Mob. Comput. Commun. Rev., 2001.10.1145\/584091.584093","DOI":"10.1145\/584091.584093"},{"key":"2022051409232290042_j_popets-2021-0078_ref_095","unstructured":"[95] Craig A. Shue, Andrew J. Kalafut, and Minaxi Gupta. The Web is Smaller Than It Seems. In IMC\u201907."},{"key":"2022051409232290042_j_popets-2021-0078_ref_096","unstructured":"[96] Sandra Siby, Marc Juarez, Claudia Diaz, Narseo Vallina-Rodriguez, and Carmela Troncoso. Encrypted DNS => Privacy? A Traffic Analysis Perspective. In NDSS \u201920."},{"key":"2022051409232290042_j_popets-2021-0078_ref_097","doi-asserted-by":"crossref","unstructured":"[97] S. Singanamalla, Suphanat Chunhapanya, Marek Vavrusa, Tanya Verma, P. Wu, Marwan Fayed, K. Heimerl, N. Sullivan, and C. Wood. Oblivious dns over https (odoh): A practical privacy enhancement to dns. In DNS Privacy Workshop 2021.10.2478\/popets-2021-0085","DOI":"10.2478\/popets-2021-0085"},{"key":"2022051409232290042_j_popets-2021-0078_ref_098","doi-asserted-by":"crossref","unstructured":"[98] Payap Sirinam, Mohsen Imani, Marc Juarez, and Matthew Wright. Deep fingerprinting: Undermining website finger-printing defenses with deep learning. In ACM Conference on Computer and Communications Security, 2018.10.1145\/3243734.3243768","DOI":"10.1145\/3243734.3243768"},{"key":"2022051409232290042_j_popets-2021-0078_ref_099","unstructured":"[99] Qixiang Sun, Daniel R. Simon, Yi-Min Wang, Wilf Russell, Venkata N. Padmanabhan, and Lili Qiu. Statistical identification of encrypted web browsing traffic. In IEEE Symposium on Security and Privacy, 2002."},{"key":"2022051409232290042_j_popets-2021-0078_ref_100","unstructured":"[100] Janos Szurdi, Balazs Kocso, Gabor Cseh, Jonathan Spring, Mark Felegyhazi, and Chris Kanich. The Long \u201cTaile\u201d of Typosquatting Domain Names. In USENIX Security \u201914."},{"key":"2022051409232290042_j_popets-2021-0078_ref_101","doi-asserted-by":"crossref","unstructured":"[101] B. Trammell, A. Wagner, and B. Claise. Flow Aggregation for the IP Flow Information Export (IPFIX) Protocol. RFC 7015, IETF, Sep 2013.10.17487\/rfc7015","DOI":"10.17487\/rfc7015"},{"key":"2022051409232290042_j_popets-2021-0078_ref_102","doi-asserted-by":"crossref","unstructured":"[102] Martino Trevisan, Idilio Drago, Marco Mellia, and Maurizio M. Munaf\u00f2. Towards web service classification using addresses and dns. In IWCMC, 2016.10.1109\/IWCMC.2016.7577030","DOI":"10.1109\/IWCMC.2016.7577030"},{"key":"2022051409232290042_j_popets-2021-0078_ref_103","doi-asserted-by":"crossref","unstructured":"[103] Martino Trevisan, Francesca Soro, M. Mellia, I. Drago, and Ricardo Morla. Does domain name encryption increase users\u2019 privacy? ACM SIGCOMM Computer Communication Review, 50:16 \u2013 22, 2020.10.1145\/3411740.3411743","DOI":"10.1145\/3411740.3411743"},{"key":"2022051409232290042_j_popets-2021-0078_ref_104","unstructured":"[104] V. Le Pochat and T. Van Goethem and S. Tajalizadehkhoob and M. Korczy\u00abski and W. Joosen. Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation. In NDSS \u201919."},{"key":"2022051409232290042_j_popets-2021-0078_ref_105","unstructured":"[105] Nino Vincenzo Verde, G. Ateniese, E. Gabrielli, L. Mancini, and A. Spognardi. No nat\u2019d user left behind: Fingerprinting users behind nat from netflow records alone. 2014 IEEE 34th International Conference on Distributed Computing Systems, pages 218\u2013227, 2014."},{"key":"2022051409232290042_j_popets-2021-0078_ref_106","unstructured":"[106] David Wagner and Bruce Schneier. Analysis of the ssl 3.0 protocol. In Workshop on Electronic Commerce, 1996."},{"key":"2022051409232290042_j_popets-2021-0078_ref_107","doi-asserted-by":"crossref","unstructured":"[107] Tao Wang. High precision open-world website fingerprinting. In IEEE S&P, 2020.10.1109\/SP40000.2020.00015","DOI":"10.1109\/SP40000.2020.00015"},{"key":"2022051409232290042_j_popets-2021-0078_ref_108","unstructured":"[108] Tao Wang, Xiang Cai, Rishab Nithyanand, Rob Johnson, and Ian Goldberg. Effective attacks and provable defenses for website fingerprinting. In USENIX Security, 2014."},{"key":"2022051409232290042_j_popets-2021-0078_ref_109","unstructured":"[109] Tao Wang and Ian Goldberg. Walkie-talkie: An efficient defense against passive website fingerprinting attacks. In USENIX Security, 2017."},{"key":"2022051409232290042_j_popets-2021-0078_ref_110","unstructured":"[110] Xiao Sophia Wang, Aruna Balasubramanian, Arvind Krishnamurthy, and David Wetherall. How speedy is SPDY? In USENIX NSDI, 2014."},{"key":"2022051409232290042_j_popets-2021-0078_ref_111","unstructured":"[111] Yixiao Xu, Tao Wang, Qi Li, Qingyuan Gong, Yang Chen, and Yong Jiang. A Multi-Tab Website Fingerprinting Attack. In ACSAC, 2018."},{"key":"2022051409232290042_j_popets-2021-0078_ref_112","unstructured":"[112] Sophia Yang. China to ban online gaming, chatting with foreigners outside Great Firewall: Report. https:\/\/www.taiwannews.com.tw\/en\/news\/3916690, 2020."},{"key":"2022051409232290042_j_popets-2021-0078_ref_113","unstructured":"[113] zzz and Lars Schimmer. Peer Profiling and Selection in the I2P Anonymous Network. In PET-CON, 2009."}],"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.sciendo.com\/pdf\/10.2478\/popets-2021-0078","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,11,6]],"date-time":"2023-11-06T12:36:12Z","timestamp":1699274172000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2021\/popets-2021-0078.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,23]]},"references-count":113,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2021,7,23]]},"published-print":{"date-parts":[[2021,10,1]]}},"alternative-id":["10.2478\/popets-2021-0078"],"URL":"https:\/\/doi.org\/10.2478\/popets-2021-0078","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,7,23]]}}}