加密流量侧信道泄漏的结构可分解性
Structural Decomposability of Encrypted Traffic Side-Channel Leakage
- School of Cyber Science and Engineering, Southeast University(东南大学网络空间安全学院)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本文提出加密流量侧信道泄漏的结构可分解框架,通过因果模型和互信息链式法则分解为大小、方向、时序三部分,并验证FRONT防御的局限,为多维防御设计提供核算方法。
AI中文摘要:
现有侧信道理论将泄漏视为整体量 $I(X;Y)$,未刻画其内部结构。本文研究加密流量侧信道泄漏的“结构可分解性”。通过结构因果模型 $X\\!\to\\!Y_{\mathrm{size}}\\!\to\\!Y_{\mathrm{dir}}\\!\to\\!Y_{\mathrm{time}}$ 及互信息链式法则,总泄漏被分解为数据包大小、方向和时序的三个序贯增量。防御被形式化为策略变量~$D$ 的机制替换;耦合信息 $C_{\mathrm{size,dir}}=I(Y_{\mathrm{size}};Y_{\mathrm{dir}}\\!\mid\\!X)$ 度量维度间依赖,马尔可夫残差为单维度防御切断下游泄漏提供可检验条件。因果效能~$\eta_d$ 量化单位成本抑制,Fisher几何近似 $I(X;Y)\approx\frac{1}{2\ln 2}\mathrm{Tr}(G\Sigma_\theta)$ 在小扰动下成立。在Wang数据集(95个网站)上,$Y_{\mathrm{dir}}$ 主导无防御泄漏(0.637比特),而Tor的固定512字节单元使 $Y_{\mathrm{size}}$ 退化;FRONT将方向项抑制63%,但其马尔可夫残差0.021比特(95%置信区间 $[0.016,0.027]$)表明无法切断时序泄漏;$\eta_{\mathrm{dir}}=0.97$ 对比 $\eta_{\mathrm{time}}\approx 0$ 证实FRONT的设计意图。这为多维联合防御设计提供了可计算、结构化的泄漏核算方法。
英文摘要:
Existing side-channel theories treat leakage as a holistic quantity $I(X;Y)$, without characterizing its internal structure. This paper studies the \emph{structural decomposability} of encrypted-traffic side-channel leakage. Via the structural causal model $X\!\to\!Y_{\mathrm{size}}\!\to\!Y_{\mathrm{dir}}\!\to\!Y_{\mathrm{time}}$ and the mutual-information chain rule, total leakage is decomposed into three sequential increments for packet size, direction, and timing. Defenses are formalized as mechanism replacement by a strategy variable~$D$; coupling information $C_{\mathrm{size,dir}}=I(Y_{\mathrm{size}};Y_{\mathrm{dir}}\!\mid\!X)$ measures inter-dimensional dependence, and the Markov residual gives a testable condition for a single-dimension defense to sever downstream leakage. Causal efficacy~$η_d$ quantifies per-unit-cost suppression, and a Fisher-geometric approximation $I(X;Y)\approx\frac{1}{2\ln 2}\mathrm{Tr}(GΣ_θ)$ holds under small perturbations. On the Wang dataset (95 websites), $Y_{\mathrm{dir}}$ dominates undefended leakage (0.637\,bits), while Tor's fixed 512-byte cells make $Y_{\mathrm{size}}$ degenerate; FRONT suppresses the direction term by 63\%, yet its Markov residual of 0.021\,bits (95\% CI $[0.016,0.027]$) shows it cannot sever timing leakage; $η_{\mathrm{dir}}=0.97$ vs. $η_{\mathrm{time}}\approx 0$ confirms FRONT's design intent. This yields a computable, structured leakage-accounting method for multi-dimensional joint defense design.