Mahdi Rahimi (KU Leuven)

Mix networks (mixnets) provide clients with communication anonymity against strong network adversaries by traversing their packets independently through randomly selected hops (mixnodes), which disrupt packet linkability. Although this approach, implemented in Nym, maximizes obfuscation against network adversaries, it enables an adversary who compromises a subset of mixnodes ($10$%/$5$% of nodes) to entirely nullify the anonymity of all clients whose communication volume with their destination exceeds a certain threshold ($4$MB/$30$MB).

To mitigate such vulnerabilities, this work develops a set of novel path selection techniques that achieve a trade-off between resistance to network adversaries and resilience against compromised mixnodes. Observing that existing anonymity metrics are insufficient to quantify adversarial risk in mixnets, we additionally introduce effective empirical and simulation-based metrics.
Through theoretical, empirical, and simulation-based evaluations, we comprehensively assess our proposals, demonstrating that the proposed approaches reduce the vulnerability to compromised nodes by up to $80%$, while conferring limited advantage to network adversaries. Our analysis further reveals that state-of-the-art anonymity metrics, in contrast to our proposed metrics, produce misleading results that influenced certain design choices in Nym.

View More Papers

NEXUS: Towards Accurate and Scalable Mapping between Vulnerabilities and...

Ehsan Khodayarseresht (Concordia University), Suryadipta Majumdar (Concordia University), Serguei Mokhov (Concordia University), Mourad Debbabi (Concordia University)

Read More

Janus: Enabling Expressive and Efficient ACLs in High-speed RDMA...

Ziteng Chen (Southeast University), Menghao Zhang (Beihang University), Jiahao Cao (Tsinghua University & Quan Cheng Laboratory), Xuzheng Chen (Zhejiang University), Qiyang Peng (Beihang University), Shicheng Wang (Unaffiliated), Guanyu Li (Unaffiliated), Mingwei Xu (Quan Cheng Laboratory & Tsinghua University & Southeast University)

Read More

A Hard-Label Black-Box Evasion Attack against ML-based Malicious Traffic...

Zixuan Liu (Tsinghua University), Yi Zhao (Beijing Institute of Technology), Zhuotao Liu (Tsinghua University and Zhongguancun Lab), Qi Li (Tsinghua University and Zhongguancun Lab), Chuanpu Fu (Tsinghua University), Guangmeng Zhou (Tsinghua University), Ke Xu (Tsinghua University and Zhongguancun Lab)

Read More