<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Complex Networks | Aqualab - Northwestern University</title><link>https://aqualab.cs.northwestern.edu/tag/complex-networks/</link><atom:link href="https://aqualab.cs.northwestern.edu/tag/complex-networks/index.xml" rel="self" type="application/rss+xml"/><description>Complex Networks</description><generator>Hugo Blox Builder (https://hugoblox.com)</generator><language>en-us</language><lastBuildDate>Mon, 01 Jun 2009 00:00:00 +0000</lastBuildDate><image><url>https://aqualab.cs.northwestern.edu/media/logo_hu_8646b2b27455bd.png</url><title>Complex Networks</title><link>https://aqualab.cs.northwestern.edu/tag/complex-networks/</link></image><item><title>Privacy in Peer-to-Peer Systems</title><link>https://aqualab.cs.northwestern.edu/project/p2p-privacy/</link><pubDate>Mon, 01 Jun 2009 00:00:00 +0000</pubDate><guid>https://aqualab.cs.northwestern.edu/project/p2p-privacy/</guid><description>&lt;div class="article-style"&gt;
&lt;h2 id="project-overview"&gt;Project Overview&lt;/h2&gt;
&lt;p&gt;Discussions of privacy in peer-to-peer systems tended to focus on content: what
a user downloads, and who can observe it. This project started from a different
place. In BitTorrent, whom you connect to is itself revealing, because people
with similar interests end up in the same swarms repeatedly, and those repeated
co-occurrences are visible to anyone watching the network.&lt;/p&gt;
&lt;p&gt;Working with Luís Amaral&amp;rsquo;s group at Northwestern, we applied community-detection
methods from complex-network analysis to BitTorrent connection patterns. The
result, reported in &lt;em&gt;Strange Bedfellows&lt;/em&gt;, is that users cluster into stable
communities that persist over time and can be recovered from connection
structure alone — no payload inspection required. An observer who cannot see
what you downloaded can still infer a great deal about what you are interested
in, simply from the company you keep.&lt;/p&gt;
&lt;p&gt;The interdisciplinary collaboration was essential here: the measurement side
supplied the traces and the systems questions, and the network-science side
supplied the methods for finding structure in them.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="swarmscreen"&gt;SwarmScreen&lt;/h2&gt;
&lt;p&gt;If connection patterns are the leak, then the defence has to operate on
connection patterns. SwarmScreen adds a controlled fraction of connections to
swarms the user has no interest in, deliberately blurring the community
structure an observer would otherwise recover.&lt;/p&gt;
&lt;p&gt;The design point is plausible deniability rather than concealment. A user&amp;rsquo;s real
activity is still there, but it is no longer separable from behaviour they never
chose, so an observer cannot attribute any particular interest with confidence.
The cost is a tunable amount of extra traffic, which the tech report examines
against the privacy gained.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="software"&gt;Software&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://aqualab.cs.northwestern.edu/project/swarmscreen/"&gt;SwarmScreen&lt;/a&gt;&lt;/strong&gt; — a Vuze extension
making downloading behaviour difficult to classify from connection patterns,
with a tunable privacy/performance trade-off.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="papers"&gt;Papers&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://aqualab.cs.northwestern.edu/publication/2010/dchoffnes-iptps10/"&gt;Strange Bedfellows: Communities in BitTorrent&lt;/a&gt; — IPTPS 2010&lt;/li&gt;
&lt;li&gt;&lt;a href="https://aqualab.cs.northwestern.edu/publication/2009/dchoffnes-nu-eecs-tr09/"&gt;SwarmScreen: Privacy Through Plausible Deniability in P2P Systems&lt;/a&gt; — Northwestern EECS technical report, 2009&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="coverage"&gt;Coverage&lt;/h2&gt;
&lt;p&gt;&lt;em&gt;The Register&lt;/em&gt; covered the work in April 2009, under
&lt;a href="https://www.theregister.com/security/2009/04/09/p2p-eavesdrop-guilt-by-association-attack-developed/758409" target="_blank" rel="noopener"&gt;&amp;ldquo;P2P eavesdrop &amp;lsquo;guilt by association attack&amp;rsquo; developed&amp;rdquo;&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="people"&gt;People&lt;/h2&gt;
&lt;p&gt;This was joint work with the &lt;a href="https://amaral.northwestern.edu/" target="_blank" rel="noopener"&gt;Amaral Lab&lt;/a&gt; at
Northwestern.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Faculty&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://aqualab.cs.northwestern.edu/author/fabian-e.-bustamante/"&gt;Fabián E. Bustamante&lt;/a&gt; (Northwestern University)&lt;/li&gt;
&lt;li&gt;Luís A. Nunes Amaral (Northwestern University)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Students&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://aqualab.cs.northwestern.edu/author/david-choffnes/"&gt;David R. Choffnes&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Collaborators&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Jordi Duch (Northwestern University)&lt;/li&gt;
&lt;li&gt;Dean Malmgren (Northwestern University)&lt;/li&gt;
&lt;li&gt;Roger Guimerà (Northwestern University)&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="related-links"&gt;Related Links&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://aqualab.cs.northwestern.edu/" target="_blank" rel="noopener"&gt;AquaLab Research Group&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;</description></item><item><title>SwarmScreen</title><link>https://aqualab.cs.northwestern.edu/project/swarmscreen/</link><pubDate>Mon, 09 Mar 2009 00:00:00 +0000</pubDate><guid>https://aqualab.cs.northwestern.edu/project/swarmscreen/</guid><description>&lt;div class="article-style"&gt;
&lt;h2 id="the-short-story"&gt;The Short Story&lt;/h2&gt;
&lt;p&gt;The goal was to make it harder for an attacker to work out your downloading
habits. Part of why BitTorrent works so well is that it lets you download from
large numbers of connections — and those same connections are opportunities for
eavesdropping. Our study of the BitTorrent network showed that user connection
patterns reveal strong communities, which enable a &lt;strong&gt;guilt-by-association
attack&lt;/strong&gt;: an entire community can be classified by monitoring one of its
members. With P2P networks increasingly under surveillance from private and
government organizations, this needed a practical answer.&lt;/p&gt;
&lt;p&gt;SwarmScreen hid real traffic in a sea of connections to randomly selected
torrents, shaping those extra connections to look like the genuine ones. It
slowed downloads, necessarily — so it offered a tuning knob, &lt;strong&gt;SPF&lt;/strong&gt;, the
SwarmScreen Protection Factor. Like sunscreen, a higher setting gives more
protection; a lower one gives back bandwidth.&lt;/p&gt;
&lt;h2 id="the-attack"&gt;The Attack&lt;/h2&gt;
&lt;p&gt;Peer-to-peer systems draw their scalability and performance from large numbers
of connections between cooperating hosts. Existing privacy work concealed
connection &lt;em&gt;data&lt;/em&gt; through encryption and trusted networks, but left the
existence of each connection visible.&lt;/p&gt;
&lt;p&gt;BitTorrent is a useful case because peers connect purely on shared, concurrent
interest in the same content — not friendship, language or geography. Using
connection patterns gathered from real users, we studied whether communities
form: collections of peers far more likely to connect to each other than to
random peers. They do, and strongly. Users inside a typical community were &lt;strong&gt;5
to 25 times more likely&lt;/strong&gt; to connect to each other than to users outside it.&lt;/p&gt;
&lt;p&gt;That structure is what makes the attack work. From &lt;strong&gt;a single observation
point&lt;/strong&gt;, an attacker could reveal &lt;strong&gt;50% of the network&lt;/strong&gt; using only knowledge of
a peer&amp;rsquo;s neighbours and their neighbours — two hops. An attacker monitoring just
&lt;strong&gt;1% of the network&lt;/strong&gt; could correctly assign users to their communities of
interest &lt;strong&gt;more than 86% of the time&lt;/strong&gt;.&lt;/p&gt;
&lt;h2 id="the-defence"&gt;The Defence&lt;/h2&gt;
&lt;p&gt;We proposed a privacy-preserving layer that obfuscates user-generated network
behaviour, and showed that plausible deniability is achievable by adding a
relatively small proportion — &lt;strong&gt;between 25% and 50%&lt;/strong&gt; — of extra random
connections, provided they are statistically indistinguishable from natural
ones. SwarmScreen generated exactly those, by participating in randomly selected
torrents without looking anomalous.&lt;/p&gt;
&lt;p&gt;Encryption does not solve this problem, because the attack reads connection
patterns rather than payloads. Tor disguises endpoints but is not built for P2P,
and downloads through it slowed by roughly a factor of ten; SwarmScreen let
users choose their own slowdown instead.&lt;/p&gt;
&lt;h2 id="why-the-name"&gt;Why the Name&lt;/h2&gt;
&lt;p&gt;SwarmScreen uses multiple swarms to screen real traffic. It also sounds like
sunscreen, which made SPF the natural name for the privacy/performance dial.&lt;/p&gt;
&lt;h2 id="availability"&gt;Availability&lt;/h2&gt;
&lt;p&gt;SwarmScreen installed into the Vuze/Azureus client, first released in March 2009,
with community translations into French, Italian, Portuguese, Slovak, Russian,
Polish, Chinese and Catalan. It is no longer available.&lt;/p&gt;
&lt;p&gt;The project shipped with a legal disclaimer worth preserving in spirit: the
privacy claims rested on the results in the technical report and were not legal
advice, and the software downloaded nothing unless the user configured it to.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="papers"&gt;Papers&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://aqualab.cs.northwestern.edu/publication/2010/dchoffnes-iptps10/"&gt;Strange Bedfellows: Communities in BitTorrent&lt;/a&gt; — IPTPS 2010&lt;/li&gt;
&lt;li&gt;&lt;a href="https://aqualab.cs.northwestern.edu/publication/2009/dchoffnes-nu-eecs-tr09/"&gt;SwarmScreen: Privacy Through Plausible Deniability in P2P Systems&lt;/a&gt; — Northwestern EECS technical report, 2009&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="coverage"&gt;Coverage&lt;/h2&gt;
&lt;p&gt;&lt;em&gt;The Register&lt;/em&gt; covered the work in April 2009, under
&lt;a href="https://www.theregister.com/security/2009/04/09/p2p-eavesdrop-guilt-by-association-attack-developed/758409" target="_blank" rel="noopener"&gt;&amp;ldquo;P2P eavesdrop &amp;lsquo;guilt by association attack&amp;rsquo; developed&amp;rdquo;&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="people"&gt;People&lt;/h2&gt;
&lt;p&gt;This was joint work with the &lt;a href="https://amaral.northwestern.edu/" target="_blank" rel="noopener"&gt;Amaral Lab&lt;/a&gt; at
Northwestern.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Faculty&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://aqualab.cs.northwestern.edu/author/fabian-e.-bustamante/"&gt;Fabián E. Bustamante&lt;/a&gt; (Northwestern University)&lt;/li&gt;
&lt;li&gt;Luís A. Nunes Amaral (Northwestern University)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Students&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://aqualab.cs.northwestern.edu/author/david-choffnes/"&gt;David R. Choffnes&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Collaborators&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Jordi Duch, Dean Malmgren, Roger Guimerà (Northwestern University)&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="related-links"&gt;Related Links&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://aqualab.cs.northwestern.edu/project/p2p-privacy/"&gt;Privacy in Peer-to-Peer Systems&lt;/a&gt; — the project SwarmScreen was built for&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;</description></item></channel></rss>