In recent years, technology has become deeply intertwined with human life. We have started to connect more devices to the internet. Information is constantly being sent over the Internet from devices we use every day, such as refrigerators, cars and implants. As we become more reliant on technology, we are developing counterparts to what we used to do offline. We are buying products online, and instead of going to the cinema or to the record store, we are using online services. Initially, the use of computers was limited to governments. As a result, much research has focused on confidentiality to keep data private. As businesses began to operate on the web, digital transactions gradually gained more importance. Consequently, researchers examined authentication to ensure the authentic user was making the transaction, not an imposter. Companies have adopted a business model based on exploiting user data in the current climate. Privacy is not enabled by default, and companies are either selling users data or processing it in order to train their artificial intelligence (AI) models. The risks of processing metadata remain relatively unknown, as many do not consider metadata to be a significant privacy risk. Most information on the web is now encrypted using TLS, and encrypted messenger applications allow two parties to communicate securely online. A common misconception is that encryption is sufficient for privacy. Unfortunately, adversaries may use traffic analysis to observe metadata and gain valuable information that could put users at risk. In addition to commercial purposes, government agencies can create dossiers on users through metadata. Furthermore, metadata has less legal protections and is machine-readable. TCP/IP leaks metadata by default because it was not designed with privacy. In the future, additional resources should be devoted toward studying anonymity as a property. Anonymity has always been an essential part of the human condition, and we need to continue to preserve it. There are various use cases for anonymous communication such as: whistleblowing, e-voting, etc. In this paper, we will look at anonymity by discussing various properties that need to be satisfied, and various attacks against anonymous communication systems. We will also give a brief history of traffic analysis and introduce some of the systems that have been used to provide anonymity to users. As for the contribution, the purpose of this thesis is to study Olvid, a messenger application which claims to be anonymous to observe its effectiveness against traffic analysis attacks. We have demonstrated that an adversary may observe other traffic features to identify user actions without decrypting user traffic.
Traffic Analysis of Secure Instant Messaging Applications
GHASEMI, REZA
2025/2026
Abstract
In recent years, technology has become deeply intertwined with human life. We have started to connect more devices to the internet. Information is constantly being sent over the Internet from devices we use every day, such as refrigerators, cars and implants. As we become more reliant on technology, we are developing counterparts to what we used to do offline. We are buying products online, and instead of going to the cinema or to the record store, we are using online services. Initially, the use of computers was limited to governments. As a result, much research has focused on confidentiality to keep data private. As businesses began to operate on the web, digital transactions gradually gained more importance. Consequently, researchers examined authentication to ensure the authentic user was making the transaction, not an imposter. Companies have adopted a business model based on exploiting user data in the current climate. Privacy is not enabled by default, and companies are either selling users data or processing it in order to train their artificial intelligence (AI) models. The risks of processing metadata remain relatively unknown, as many do not consider metadata to be a significant privacy risk. Most information on the web is now encrypted using TLS, and encrypted messenger applications allow two parties to communicate securely online. A common misconception is that encryption is sufficient for privacy. Unfortunately, adversaries may use traffic analysis to observe metadata and gain valuable information that could put users at risk. In addition to commercial purposes, government agencies can create dossiers on users through metadata. Furthermore, metadata has less legal protections and is machine-readable. TCP/IP leaks metadata by default because it was not designed with privacy. In the future, additional resources should be devoted toward studying anonymity as a property. Anonymity has always been an essential part of the human condition, and we need to continue to preserve it. There are various use cases for anonymous communication such as: whistleblowing, e-voting, etc. In this paper, we will look at anonymity by discussing various properties that need to be satisfied, and various attacks against anonymous communication systems. We will also give a brief history of traffic analysis and introduce some of the systems that have been used to provide anonymity to users. As for the contribution, the purpose of this thesis is to study Olvid, a messenger application which claims to be anonymous to observe its effectiveness against traffic analysis attacks. We have demonstrated that an adversary may observe other traffic features to identify user actions without decrypting user traffic.| File | Dimensione | Formato | |
|---|---|---|---|
|
Ghasemi_Reza.pdf
Accesso riservato
Dimensione
1.18 MB
Formato
Adobe PDF
|
1.18 MB | Adobe PDF |
The text of this website © Università degli studi di Padova. Full Text are published under a non-exclusive license. Metadata are under a CC0 License
https://hdl.handle.net/20.500.12608/115861