A system and method is provided for evaluating the effectiveness of data
encryption for hiding the identity of the source of Web traffic. A
signature is constructed from encrypted Web traffic for a Web page sent
by a target Web site, and the signature is compared with archived traffic
signatures obtained by accessing various Web pages of interest in
advance. If the signature of the detected encrypted Web traffic matches a
stored traffic signature beyond a pre-set statistical threshold, a
positive match is found, and the source of the traffic is identified.
Countermeasures for reducing the reliability of source identification
based on traffic signature matching are provided.