Rob Jansen

dblp:14/7561 · DBLP profile ↗
← Back
39ranked-venue papers
22as first author
20since 2021 · last 2026
0000-0002-4406-997XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 36 · 21 first-author · 18 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Computer networks · 1
YearPublicationVenuePosition
2026 CELLSHIFT: RTT-Aware Trace Transduction for Real-World Website Fingerprinting
Rob Jansen
NDSS1
2026 A Measurement of Genuine Tor Traces for Realistic Website Fingerprinting
Rob Jansen, Ryan Wails, Aaron Johnson 0001
PAM1
2026 Editors' Introduction
abstract
Editors' Introduction, Issue 1 of PoPETs Volume 2026
Gunes Acar, Rob Jansen
Proc. Priv. Enhancing Technol.2
2026 Editors' Introduction
abstract
Editors' Introduction, Issue 2 of PoPETs Volume 2026
Gunes Acar, Rob Jansen
Proc. Priv. Enhancing Technol.2
2026 Editors' Introduction
abstract
Editors' Introduction, Issue 3 of PoPETs Volume 2026
Gunes Acar, Rob Jansen
Proc. Priv. Enhancing Technol.2
2026 Editors' Introduction
abstract
Editors' Introduction, Issue 4 of PoPETs Volume 2026
Gunes Acar, Rob Jansen
Proc. Priv. Enhancing Technol.2
2025 Censorship Evasion with Unidentified Protocol Generation
Ryan Wails, Rob Jansen, Aaron Johnson 0001, Micah Sherr
USENIX Security Symposium2
2025 Editors' Introduction
abstract
Editors' Introduction, Issue 1 of PETS Volume 2025
Rob Jansen, Zubair Shafiq
Proc. Priv. Enhancing Technol.1
2025 Editors' Introduction
abstract
Editors' Introduction, Issue 2 of PETS Volume 2025
Rob Jansen, Zubair Shafiq
Proc. Priv. Enhancing Technol.1
2025 Editors' Introduction
abstract
Editors' Introduction, Issue 3 of PETS Volume 2025
Rob Jansen, Zubair Shafiq
Proc. Priv. Enhancing Technol.1
2025 Editors' Introduction
abstract
Editors' Introduction, Issue 4 of PETS Volume 2025
Rob Jansen, Zubair Shafiq
Proc. Priv. Enhancing Technol.1
2025 Onion-Location Measurements and Fingerprinting
abstract
Onion-Location makes it easy for websites offering onion service access to support automatic discovery in Tor Browser of the random-looking onion address associated with their domain. We provide the first measurement study of how many websites are currently using Onion-Location. We also describe the open-source tools we created to conduct the study. Onion-Location has been criticized elsewhere for its lack of transparency and vulnerability to blocking. Perhaps even more troubling, we show that Onion-Location is vulnerable to very accurate fingerprinting. We present recommended changes to and alternatives to Onion-Location as well as steps towards even more secure onion discovery and association.
Paul F. Syverson, Rasmus Dahlberg, Tobias Pulls, Rob Jansen
Proc. Priv. Enhancing Technol.4
2024 On Precisely Detecting Censorship Circumvention in Real-World Networks
Ryan Wails, George Arnold Sullivan, Micah Sherr, Rob Jansen
NDSS4
2023 Data-Explainable Website Fingerprinting with Network Simulation
abstract
Website fingerprinting (WF) attacks allow an adversary to associate a website with the encrypted traffic patterns produced when accessing it, thus threatening to destroy the client-server unlinkability promised by anonymous communication networks. Explainable WF is an open problem in which we need to improve our understanding of (1) the machine learning models used to conduct WF attacks; and (2) the WF datasets used as inputs to those models. This paper focuses on explainable datasets; that is, we develop an alternative to the standard practice of gathering low-quality WF datasets using synthetic browsers in large networks without controlling for natural network variability. In particular, we demonstrate how network simulation can be used to produce explainable WF datasets by leveraging the simulator's high degree of control over network operation. Through a detailed investigation of the effect of network variability on WF performance, we find that: (1) training and testing WF attacks in networks with distinct levels of congestion increases the false-positive rate by as much as 200%; (2) augmenting the WF attacks by training them across several networks with varying degrees of congestion decreases the false-positive rate by as much as 83%; and (3) WF classifiers trained on completely simulated data can achieve greater than 80% accuracy when applied to the real world.
Rob Jansen, Ryan Wails
Proc. Priv. Enhancing Technol.1
2022 Co-opting Linux Processes for High-Performance Network Simulation
Rob Jansen, James Newsome, Ryan Wails
USENIX ATC1
2022 Online Website Fingerprinting: Evaluating Website Fingerprinting Attacks on Tor in the Real World
Giovanni Cherubin, Rob Jansen, Carmela Troncoso
USENIX Security Symposium2
2022 Learning to Behave: Improving Covert Channel Security with Behavior-Based Designs
abstract
Censorship-resistant communication systems generally use real-world cover protocols to establish a covert channel through which uncensored communication can occur. Unfortunately, many previously proposed systems use cover protocols inconsistently with the way humans normally use those protocols, leading to anomalous network traffic patterns that have been shown to be discoverable by real-world censors. In this paper, we argue that censorship-resistant communication systems should follow two behavior-based design properties: (i) behavioral independence: systems should isolate the operation of their covert channels from the operation of their cover protocols, and (ii) behavioral realism: systems should either opportunistically use existing genuine cover protocol instances or run new protocol instances that are modeled after genuine ones. These properties ensure that the behavior of a system’s users will not degrade its security. We demonstrate how to achieve these properties through the design and evaluation of Raven, a censorship-resistant messaging system that uses email cover protocols identically to the way humans use email. Raven uses a generative adversarial network that is trained on genuine email data to control the timing and sizes of the email messages it sends and receives, and these messages are transferred independently of user actions. Our evaluation shows that, compared to the state-of-the-art email-based Mailet system, Raven raises the false-positive rate from 3% to 50% when detecting covert channel usage with 100% recall.
Ryan Wails, Andrew Stange, Eliana Troper, Aylin Caliskan, Roger Dingledine, Rob Jansen, Micah Sherr
Proc. Priv. Enhancing Technol.6
2021 FlashFlow: A Secure Speed Test for Tor
abstract
The Tor network uses a measurement system called TorFlow to estimate its relays' forwarding capacity and to balance traffic among them. This system has been shown to be vulnerable to adversarial manipulation, and inaccuracies even in benign circumstances have long been observed. To solve the issues with security and accuracy, we present FlashFlow, a system to measure the capacity of Tor relays. Our analysis shows that FlashFlow limits a malicious relay to obtaining a capacity estimate at most 1.33 times its true capacity. Through realistic Internet experiments, we find that FlashFlow measures relay capacity with$\geq {89\%}$accuracy 95 % of the time. Through simulation, we find that FlashFlow can measure the entire Tor network in less than 5 hours using 3 measurers with 1 Gbit/s of bandwidth each. Performance simulations using FlashFlow for load balancing shows that, compared to TorFlow, network weight error decreases by 86 %, while the median of 50 KiB, 1 MiB, and 5 MiB transfer times decreases by 15 %, 29 %, and 37 %, respectively. Moreover, FlashFlow yields more consistent client performance: the median rate of transfer timeouts decreases by 100 %, while the standard deviation of 50 KiB, 1 MiB, and 5 MiB transfer times decreases by 55%, 61 %, and 41 %, respectively. We also find that the performance improvements increase relative to TorFlow as the total client-traffic load increases, demonstrating that FlashFlow is better suited to supporting network growth.
Matthew Traudt, Rob Jansen, Aaron Johnson 0001
ICDCS2
2021 On the Accuracy of Tor Bandwidth Estimation
Rob Jansen, Aaron Johnson 0001
PAM1
2021 Once is Never Enough: Foundations for Sound Statistical Inference in Tor Network Experimentation
Rob Jansen, Justin Tracey, Ian Goldberg 0001
USENIX Security Symposium1
2019 Point Break: A Study of Bandwidth Denial-of-Service Attacks against Tor
Rob Jansen, Tavish Vaidya, Micah Sherr
USENIX Security Symposium1
2019 KIST: Kernel-Informed Socket Transport for Tor
abstract
Tor’s growing popularity and user diversity has resulted in network performance problems that are not well understood, though performance is understood to be a significant factor in Tor’s security. A large body of work has attempted to solve performance problems without a complete understanding of where congestion occurs in Tor. In this article, we first study congestion in Tor at individual relays as well as along the entire end-to-end Tor path and find that congestion occurs almost exclusively in egress kernel socket buffers. We then analyze Tor’s socket interactions and discover two major contributors to Tor’s congestion: Tor writes sockets sequentially, and Tor writes as much as possible to each socket. To improve Tor’s performance, we design, implement, and test KIST: a new socket management algorithm that uses real-time kernel information to dynamically compute the amount to write to each socket while considering all circuits of all writable sockets when scheduling cells. We find that, in the medians, KIST reduces circuit congestion by more than 30%, reduces network latency by 18%, and increases network throughput by nearly 10%. We also find that client and relay performance with KIST improves as more relays deploy it and as network load and packet loss rates increase. We analyze the security of KIST and find an acceptable performance and security tradeoff, as it does not significantly affect the outcome of well-known latency, throughput, and traffic correlation attacks. KIST has been merged and configured as the default socket scheduling algorithm in Tor version 0.3.2.1-alpha (released September 18, 2017) and became stable in Tor version 0.3.2.9 (released January 9, 2018). While our focus is Tor, our techniques and observations should help analyze and improve overlay and application performance, both for security applications and in general.
Rob Jansen, Matthew Traudt, John Geddes, Chris Wacek, Micah Sherr, Paul F. Syverson
ACM Trans. Priv. Secur.1
2018 Privacy-Preserving Dynamic Learning of Tor Network Traffic
abstract
Experimentation tools facilitate exploration of Tor performance and security research problems and allow researchers to safely and privately conduct Tor experiments without risking harm to real Tor users. However, researchers using these tools configure them to generate network traffic based on simplifying assumptions and outdated measurements and without understanding the efficacy of their configuration choices. In this work, we design a novel technique for dynamically learning Tor network traffic models using hidden Markov modeling and privacy-preserving measurement techniques. We conduct a safe but detailed measurement study of Tor using 17 relays (~2% of Tor bandwidth) over the course of 6 months, measuring general statistics and models that can be used to generate a sequence of streams and packets. We show how our measurement results and traffic models can be used to generate traffic flows in private Tor networks and how our models are more realistic than standard and alternative network traffic generation~methods.
Rob Jansen, Matthew Traudt, Nicholas Hopper
CCS1
2018 Understanding Tor Usage with Privacy-Preserving Measurement
Akshaya Mani, T. Wilson-Brown, Rob Jansen, Aaron Johnson 0001, Micah Sherr
Internet Measurement Conference3
2018 Inside Job: Applying Traffic Analysis to Measure Tor from Within
Rob Jansen, Marc Juarez, Rafa Gálvez, Tariq Elahi, Claudia Díaz
NDSS1
2017 Avoiding The Man on the Wire: Improving Tor's Security with Trust-Aware Path Selection
Aaron Johnson 0001, Rob Jansen, Aaron D. Jaggard, Joan Feigenbaum, Paul F. Syverson
NDSS2
2017 PeerFlow: Secure Load Balancing in Tor
abstract
Abstract We present PeerFlow, a system to securely load balance client traffic in Tor. Security in Tor requires that no adversary handle too much traffic. However, Tor relays are run by volunteers who cannot be trusted to report the relay bandwidths, which Tor clients use for load balancing. We show that existing methods to determine the bandwidths of Tor relays allow an adversary with little bandwidth to attack large amounts of client traffic. These methods include Tor’s current bandwidth-scanning system, TorFlow, and the peer-measurement system EigenSpeed. We present an improved design called PeerFlow that uses a peer-measurement process both to limit an adversary’s ability to increase his measured bandwidth and to improve accuracy. We show our system to be secure, fast, and efficient. We implement PeerFlow in Tor and demonstrate its speed and accuracy in large-scale network simulations.
Aaron Johnson 0001, Rob Jansen, Nicholas Hopper, Aaron Segal, Paul F. Syverson
Proc. Priv. Enhancing Technol.2
2016 Safely Measuring Tor
abstract
Tor is a popular network for anonymous communication. The usage and operation of Tor is not well-understood, however, because its privacy goals make common measurement approaches ineffective or risky. We present PrivCount, a system for measuring the Tor network designed with user privacy as a primary goal. PrivCount securely aggregates measurements across Tor relays and over time to produce differentially private outputs. PrivCount improves on prior approaches by enabling flexible exploration of many diverse kinds of Tor measurements while maintaining accuracy and privacy for each. We use PrivCount to perform a measurement study of Tor of sufficient breadth and depth to inform accurate models of Tor users and traffic. Our results indicate that Tor has 710,000 users connected but only 550,000 active at a given time, that Web traffic now constitutes 91% of data bytes on Tor, and that the strictness of relays' connection policies significantly affects the type of application data they forward.
Rob Jansen, Aaron Johnson 0001
CCS1
2015 WPES 2015: The 14th Workshop on Privacy in the Electronic Society
abstract
We present a brief summary of The 14th Workshop on Privacy in the Electronic Society, held on October 12th, 2015, in conjunction with the 22nd ACM Conference on Computer and Communications Security in Denver, Colorado, USA. The goal of this workshop is to discuss the problems of privacy in the global interconnected societies and possible solutions to them. The workshop program includes 11 full papers and 3 short papers out of 32 total submissions. Specific areas that are covered in the program include, but are not limited to: web and social network privacy, mobile and location privacy, communications privacy, and privacy-preserving data analysis.
Nicholas Hopper, Rob Jansen
CCS2
2014 The Sniper Attack: Anonymously Deanonymizing and Disabling the Tor Network
Rob Jansen, Florian Tschorsch, Aaron Johnson 0001, Björn Scheuermann 0001
NDSS1
2014 Never Been KIST: Tor's Congestion Management Blossoms with Kernel-Informed Socket Transport
Rob Jansen, John Geddes, Chris Wacek, Micah Sherr, Paul F. Syverson
USENIX Security Symposium1
2013 Users get routed: traffic correlation on tor by realistic adversaries
abstract
We present the first analysis of the popular Tor anonymity network that indicates the security of typical users against reasonably realistic adversaries in the Tor network or in the underlying Internet. Our results show that Tor users are far more susceptible to compromise than indicated by prior work. Specific contributions of the paper include(1)a model of various typical kinds of users,(2)an adversary model that includes Tor network relays, autonomous systems(ASes), Internet exchange points (IXPs), and groups of IXPs drawn from empirical study,(3) metrics that indicate how secure users are over a period of time,(4) the most accurate topological model to date of ASes and IXPs as they relate to Tor usage and network configuration,(5) a novel realistic Tor path simulator (TorPS), and(6)analyses of security making use of all the above. To show that our approach is useful to explore alternatives and not just Tor as currently deployed, we also analyze a published alternative path selection algorithm, Congestion-Aware Tor. We create an empirical model of Tor congestion, identify novel attack vectors, and show that it too is more vulnerable than previously indicated.
Aaron Johnson 0001, Chris Wacek, Rob Jansen, Micah Sherr, Paul F. Syverson
CCS3
2013 LIRA: Lightweight Incentivized Routing for Anonymity
Rob Jansen, Aaron Johnson 0001, Paul F. Syverson
NDSS1
2013 How Low Can You Go: Balancing Performance with Anonymity in Tor
John Geddes, Rob Jansen, Nicholas Hopper
Privacy Enhancing Technologies2
2012 Shadow: Running Tor in a Box for Accurate and Efficient Experimentation
Rob Jansen, Nicholas Hopper
NDSS1
2012 Throttling Tor Bandwidth Parasites
Rob Jansen, Nicholas Hopper, Paul F. Syverson
NDSS1
2012 Throttling Tor Bandwidth Parasites
Rob Jansen, Paul F. Syverson, Nicholas Hopper
USENIX Security Symposium1
2010 Recruiting new tor relays with BRAIDS
abstract
Tor, a distributed Internet anonymizing system, relies on volunteers who run dedicated relays. Other than altruism, these volunteers have no incentive to run relays, causing a large disparity between the number of users and available relays. We introduce BRAIDS, a set of practical mechanisms that encourages users to run Tor relays, allowing them to earn credits redeemable for improved performance of both interactive and non-interactive Tor traffic. These performance incentives will allow Tor to support increasing resource demands with almost no loss in anonymity: BRAIDS is robust to well-known attacks. Using a simulation of 20,300 Tor nodes, we show that BRAIDS allows relays to achieve 75% lower latency than non-relays for interactive traffic, and 90% higher bandwidth utilization for non-interactive traffic.
Rob Jansen, Nicholas Hopper, Yongdae Kim
CCS1
2009 Membership-concealing overlay networks
abstract
We introduce the concept of membership-concealing overlay networks (MCONs), which hide the real-world identities of participants. We argue that while membership concealment is orthogonal to anonymity and censorship resistance, pseudonymous communication and censorship resistance become much easier if done over a membership-concealing network. We formalize the concept of membership concealment, discuss a number of attacks against existing systems and present real-world attack results. We then propose three proof-of-concept MCON designs that resist those attacks: one that is more efficient, another that is more robust to membership churn, and a third that balances efficiency and robustness. We show theoretical and simulation results demonstrating the feasibility and performance of our schemes.
Eugene Y. Vasserman, Rob Jansen, James Tyra, Nicholas Hopper, Yongdae Kim
CCS2