safing / portmaster

🏔 Love Freedom - ❌ Block Mass Surveillance
https://safing.io
GNU General Public License v3.0
8.77k stars 274 forks source link

Add Maybenot(A Framework for Traffic Analysis Defenses) for SPN. #1581

Open Noir16 opened 2 weeks ago

Noir16 commented 2 weeks ago

What would you like to add or change?: I look forward to the addition of vulnerability prevention through AI and data pattern inference to the SPN network.

Why do you and others need this?: I suggest introducing technology to prevent data leakage in the form of inferring data packet transmission patterns. As AI evolves, we will likely need to adopt techniques to prevent these vulnerabilities by mixing in fake network noise to counter the risk of inferring advanced data patterns to reveal the true path.

This technology will take some time to stabilize and is not an immediate threat, so we recommend adopting it after a thorough internal review.

scholarly resource: https://dl.acm.org/doi/abs/10.1145/3603216.3624953

evaluation resource(with Mullvad VPN): https://pulls.name/blog/2024-06-05-eval-first-daita-servers/

Raphty commented 2 weeks ago

we have designed SPN from the start to be as resistant as possible to traffic analysis.

TBH VPNs have been vulnerable to this way before.

Look in our whitepaper and the wiki https://safing.io/files/whitepaper/Gate17.pdf https://wiki.safing.io/en/Portmaster/Feature/AvoidTrafficAnalysis

We welcome anyone who wants to test this as well. Please get in touch beforehand!