<?xml version="1.0" standalone="no"?>
                    <!DOCTYPE div SYSTEM "/www/backend/www-xml-443/dtd/caidaML.dtd">
                    <!-- do NOT ERASE the DOCTYPE declaration! --><div>


<tr bgcolor="#f4f4f4">
  <td>
<font face="helvetica,arial" size="2">
<b>URL:</b>
</font>
</td>
  <td>
<font face="helvetica,arial" size="2">
<a href="http://citeseer.ist.psu.edu/serjantov02towards.html">http://citeseer.ist.psu.edu/serjantov02towards.html</a>
</font>
  </td>
</tr>


<tr bgcolor="#e9e9e9">
  <td>
<font face="helvetica,arial" size="2">
<b>ENTRY DATE:</b>
</font>
</td>
  <td>
<font face="helvetica,arial" size="2">
2008-06-16


</font>
  </td>
</tr>


<tr bgcolor="#f4f4f4">
  <td>
<font face="helvetica,arial" size="2">
<b>ABSTRACT:</b>
</font>
</td>
  <td>
<font face="helvetica,arial" size="2">
In this paper we look closely at the popular metric of anonymity, the
anonymity set, and point out a number of problems associated with it. We
then propose an alternative information theoretic measure of anonymity
which takes into account the probabilities of users sending and
receiving the messages and show how to calculate it for a message in a
standard mix-based anonymity system. We also use our metric to compare a
pool mix to a traditional threshold mix, which was impossible using
anonymity sets. We also show how the maximum route length restriction
which exists in some fielded anonymity systems can lead to the attacker
performing more powerful traffic analysis. Finally, we discuss open
problems and future work on anonymity measurements.



</font>
  </td>
</tr>
</div>

