Software improves p2p privacy by hiding in the crowd

April 8, 2009

Researchers at the McCormick School of Engineering and Applied Science at Northwestern University have identified a new "guilt-by-association" threat to privacy in peer-to-peer (P2P) systems that would enable an eavesdropper to accurately classify groups of users with similar download behavior. To thwart this threat, they have released publicly available, open source software that restores privacy by masking a user's real download activity in such a manner as to disrupt classification.

P2P systems are incredibly popular, enabling new and important Internet applications such as voice over IP (VoIP) and file sharing. These systems work by establishing network connections between machines that cooperate to perform a common goal. While many researchers have pointed out that the data exchanged over these connections can reveal personal information about users, an interdisciplinary collaboration between Fabián Bustamante, associate professor of electrical engineering and computer science, Luis Amaral, associate professor of chemical and biological engineering, and Roger Guimerà, research assistant professor of chemical and biological engineering, shows that only the patterns of connections — not the data itself — is sufficient to create a powerful threat to user privacy.

The team of researchers, which includes graduate students David Choffnes (electrical engineering and computer science) and Dean Malmgren (chemical and biological engineering), and postdoctoral fellow Jordi Duch (chemical and biological engineering), studied connection patterns in the BitTorrent file-sharing network — one of the largest and most popular P2P systems today. They found that over the course of weeks, groups of users formed communities where each member consistently connected with other community members more than with users outside the community.

"This was particularly surprising because BitTorrent is designed to establish connections at random, so there is no a priori reason for such strong communities to exist," Bustamante says. After identifying this community behavior, the researchers showed that an eavesdropper could classify users into specific communities using a relatively small number of observation points. Indeed, a savvy attacker can correctly extract communities more than 85 percent of the time by observing only 0.01 percent of the total users. Worse yet, this information could be used to launch a "guilt-by-association" attack, where an attacker need only determine the downloading behavior of one user in the community to convincingly argue that all users in the communities are doing the same.

Given the impact of this threat, the researchers developed a technique that prevents accurate classification by intelligently hiding user-intended downloading behavior in a cloud of random downloading. They showed that this approach causes an eavesdropper's classification to be wrong the majority of the time, providing users with grounds to claim "plausible deniability" if accused.

The research team implemented this strategy in software that has already been made available as a seamless extension to the popular Vuze BitTorrent client. The software, named SwarmScreen, downloads randomly-selected content in a way that prevents eavesdroppers from distinguishing it from user-desired content. SwarmScreen allows users to control the impact of these connections on the download performance for the data they want to keep.

More information: SwarmScreen is available for download on the Aqualab website or via the Vuze plugin installation menu. For more details about this work, visit http://aqualab.cs.northwestern.edu/projects/SwarmScreen.html

Source: Northwestern University (news : web)


   
Rate this story - 4.3 /5 (3 votes)


April 8, 2009 all stories

Comments: 0

4.3 /5 (3 votes)

  • hide
  • Related Stories

  • New software allows ISPs and P2P users to get along without getting too cozy
    created May 02, 2008 | popularity not rated yet | comments 0
  • Developing a neighborhood watch for the Internet
    created Nov 24, 2008 | popularity not rated yet | comments 0
  • BitTorrent gaining more acceptance
    created Apr 20, 2006 | popularity not rated yet | comments 0
  • The 5 dimensions of online gifts
    created Jun 13, 2007 | popularity not rated yet | comments 0
  • Computer scientists develop P2P system that promises faster music, movie downloads
    created Apr 10, 2007 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Computer 5V or 0V output to Sensaphone Express II
    created Feb 04, 2010
  • Ti-89 ROM Image
    created Jan 29, 2010
  • TV ads
    created Jan 29, 2010
  • Apple introduces latest iNonsense
    created Jan 27, 2010
  • More from Physics Forums - Computing & Technology

Other News

A general view of the arrival area of the Whistler Creek Alpine Skiing venue

Google Maps climbs to Olympic peaks

Technology / Internet

created 2 minutes ago | popularity not rated yet | comments 0

Google sent snowmobiles rigged with cameras into Canadian mountains so folks snug and warm at home will get views of slopes at the Winter Olympic Games kicking off on Friday.


Warner CEO sees e-book 'fracas' as helping music

Technology / Business

created 1hour ago | popularity not rated yet | comments 0

(AP) -- The head of Warner Music Group expressed hope on Tuesday that the recent "fracas" over the price of e-books would help give content creators such as his company more pricing power over device makers.


PayPal's India transaction block could last months

Technology / Business

created 42 minutes ago | popularity not rated yet | comments 0

(AP) -- Online payments service PayPal says its suspension of certain transactions in India could last months.


The power of 'random'

The power of 'random': 'Seemingly loopy' technique could dramatically improve communications networks

Technology / Computer Sciences

created 9 hours ago | popularity 4.8 / 5 (5) | comments 4 | with audio podcast

A radical new approach to the design of communications networks, called "network coding," promises to make Internet file sharing faster, streaming video more reliable, and cell-phone reception better -- among ...


Spanish Minister of industry Miguel Sebastian (C) sits in an electric car with Jean Pierre Laurent

EU ministers call for common electric car strategy

Technology / Energy

created 1hour ago | popularity not rated yet | comments 0

EU industry ministers on Tuesday pressed the European Commission to establish a common strategy to develop electric cars.