Defending Tor from Network Adversaries: A Case Study of Network Path Prediction

Defending Tor from Network Adversaries: A Case Study of Network Path Prediction
复制标题

防御 Tor 免受网络对手的攻击:网络路径预测案例研究

DOI:
--
复制
发表时间:
2014
影响因子:
--
通讯作者:
M. Caesar
M. Caesar
中科院分区:
--
文献类型:
--
作者:
Joshua Juen;Aaron Johnson;Anupam Das;N. Borisov;M. Caesar

文献摘要

被引文献

相似文献

摘要Tor匿名网络已被证明容易受到自治系统(AS)和互联网交换机(IX)的流量分析攻击,它们可以观察属于同一电路的不同覆盖跳数。我们评估网络路径预测技术是否提供了来自这些对手的威胁的准确图片,以及它们是否可以用来避免这种威胁。我们通过收集1720万个从Tor中继到互联网目的地的跟踪路由来进行测量研究。我们比较收集的traceroute路径预测路径使用国家的最先进的路径推理技术。我们发现,跟踪路由呈现出一个非常不同的画面,与一组AS看到的跟踪路由路径不同的预测路径的80%的时间。我们还考虑了预测错误对Tor安全性的影响。使用模拟器在一周内选择路径,我们的跟踪路由表明,用户在一周内至少有一次妥协的机会接近100%,其中11%的路径包含AS妥协,而使用默认Tor选择时,包含IX妥协的路径不到1%。我们发现,修改路径选择,选择预测为安全的路径降低了总路径与AS妥协到0.14%,但仍然提出了一个5-11%的机会,至少有一个妥协在一周内,而使5%的路径失败,与96%的失败,由于误报路径推断。我们的研究结果表明,更多的测量和更好的路径预测是必要的,以减轻AS和IX对手对Tor的风险。
Abstract The Tor anonymity network has been shown vulnerable to traffic analysis attacks by autonomous systems (ASes) and Internet exchanges (IXes), which can observe different overlay hops belonging to the same circuit. We evaluate whether network path prediction techniques provide an accurate picture of the threat from such adversaries, and whether they can be used to avoid this threat. We perform a measurement study by collecting 17.2 million traceroutes from Tor relays to destinations around the Internet. We compare the collected traceroute paths to predicted paths using state-of-the-art path inference techniques. We find that traceroutes present a very different picture, with the set of ASes seen in the traceroute path differing from the predicted path 80% of the time. We also consider the impact that prediction errors have on Tor security. Using a simulator to choose paths over a week, our traceroutes indicate a user has nearly a 100% chance of at least one compromise in a week with 11% of total paths containing an AS compromise and less than 1% containing an IX compromise when using default Tor selection. We find modifying the path selection to choose paths predicted to be safe lowers total paths with an AS compromise to 0.14% but still presents a 5–11% chance of at least one compromise in a week while making 5% of paths fail, with 96% of failures due to false positives in path inferences. Our results demonstrate more measurement and better path prediction is necessary to mitigate the risk of AS and IX adversaries to Tor.