kth.sePublications KTH
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Mitigating Traffic Analysis Attacks While Maintaining On-Path Network Observability
KTH, School of Electrical Engineering and Computer Science (EECS), Computer Science, Theoretical Computer Science, TCS. Ericsson AB, Stockholm, Sweden.ORCID iD: 0009-0009-0088-6642
KTH, School of Electrical Engineering and Computer Science (EECS), Computer Science, Theoretical Computer Science, TCS. KTH, School of Electrical Engineering and Computer Science (EECS), Centres, Digital futures.ORCID iD: 0000-0002-8069-6495
KTH, School of Electrical Engineering and Computer Science (EECS), Computer Science, Network and Systems Engineering. KTH, School of Electrical Engineering and Computer Science (EECS), Centres, Digital futures.ORCID iD: 0000-0002-4876-0223
2026 (English)In: Secure IT Systems - 30th Nordic Conference, NordSec 2025, Proceedings, Springer Nature , 2026, p. 246-265Conference paper, Published paper (Refereed)
Abstract [en]

Concealing distinguishing features in traffic patterns used in Traffic Analysis (TA) attacks also affects network observability and hence it is detrimental for legitimate traffic analysis (e.g., network monitoring, anomaly detection). The problem is particularly relevant in microservice-based cloud-native systems. In this paper we introduce a novel method that defends traffic flows against TA attacks and selectively exposes metadata to allow semi-trusted entities to recover certain traffic characteristics with low additional overhead by using a surplus area in the packets. In our architecture, proxies protect traffic between microservices using application-level logic and protocol features. We provide a PoC implementation and evaluation of the proposed method using the QUIC and HTTP/3 protocols for two network functions in the 5G Core Network and in a microservice benchmark application. We show that two events can be made indistinguishable for a storage channel attacker, while maintaining observability for a legitimate TA node. We also extend our defense to reduce the accuracy of a more powerful (timing channel) attacker by 20–30%.

Place, publisher, year, edition, pages
Springer Nature , 2026. p. 246-265
Keywords [en]
Network monitoring, Network Protocols, Security and Privacy Protection, Traffic analysis
National Category
Computer Sciences Security, Privacy and Cryptography
Identifiers
URN: urn:nbn:se:kth:diva-382373DOI: 10.1007/978-3-032-14782-0_14Scopus ID: 2-s2.0-105036737625OAI: oai:DiVA.org:kth-382373DiVA, id: diva2:2062675
Conference
30th Nordic Conference on Secure IT Systems, NordSec 2025, Tartu, Estonia, November 12-13, 2025
Note

Part of ISBN 9783032147813

QC 20260526

Available from: 2026-05-26 Created: 2026-05-26 Last updated: 2026-05-26Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full textScopus

Authority records

Kövér, JánosGuanciale, RobertoDán, György

Search in DiVA

By author/editor
Kövér, JánosGuanciale, RobertoDán, György
By organisation
Theoretical Computer Science, TCSDigital futuresNetwork and Systems Engineering
Computer SciencesSecurity, Privacy and Cryptography

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 40 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf