digital8 Second Lieutenant
Joined: 29 Sep 2005
Posts: 1002
|
Posted: Sat Oct 01, 2005 2:28 pm Post subject: Watching the traffic go by |
|
|
Sophisticated traffic analysis could trivially defeat the protection provided by the remailer network in its current configuration. An agent could monitor the network itself, examining and recording message sizes, message timing, and message contents. Sophisticated traffic analysis would require an analysis of all of the network traffic in and out of all the remailers. For some agencies and organizations, with sufficient manpower and computing resources, this sort of approach is highly possible.
How would this sort of traffic monitoring work? What kind of information would be secured? First, an agent would monitor message times. Simply, the time at which a message enters and leaves a network would be recorded. Second, an agent would analyze message sizes. In a standard remailer chain, message sizes decrease by a predictable amount at each hop along the chain. Finally, an agent could determine the actual identity of a reply block by using a spamming the network. Spamming - sending a large number of unwanted messages - in this case would use a given reply block. In combination with analyses of message times and sizes, this approach could provide much useful information to an agent. |
|