Honey Onions: A framework for characterizing and identifying misbehaving Tor HSDirs

Honey Onions: A framework for characterizing and identifying misbehaving Tor HSDirs
复制标题

DOI:
10.1109/cns.2016.7860478
复制
发表时间:
2016-10
期刊:
2016 IEEE Conference on Communications and Network Security (CNS)
影响因子:
--
通讯作者:
Amirali Sanatinia;G. Noubir
Amirali Sanatinia;G. Noubir
中科院分区:
其他
文献类型:
--
作者:
Amirali Sanatinia;G. Noubir

文献摘要

被引文献

相似文献

在过去的十年中,Tor 被证明是一个非常成功且广泛流行的保护用户匿名的系统。然而,Tor 仍然是一个具有各种局限性的实用系统,其中一些局限性在最近确实被利用了。特别是,Tor 的安全性依赖于其大量节点不会行为不当这一事实。在这项工作中,我们介绍了 Honey Onion 的概念,这是一个利用 HSDir 功能检测行为不当的 Tor 中继的框架。这允许获得中继之间不当行为的下限。我们提出了算法来估计窥探 HSDir 的数量并识别最有可能的窥探者。我们的实验结果表明,在研究期间(72 天),至少有 110 个此类节点正在窥探有关其托管的隐藏服务的信息。我们发现,其中一半以上托管在云基础设施上,并延迟了所学信息的使用,以防止轻松追溯。
In the last decade, Tor proved to be a very successful and widely popular system to protect users' anonymity. However, Tor remains a practical system with a variety of limitations, some of which were indeed exploited in the recent past. In particular, Tor's security relies on the fact that a substantial number of its nodes do not misbehave. In this work we introduce, the concept of honey onions, a framework to detect misbehaving Tor relays with HSDir capability. This allows to obtain lower bounds on misbehavior among relays. We propose algorithms to both estimate the number of snooping HSDirs and identify the most likely snoopers. Our experimental results indicate that during the period of the study (72 days) at least 110 such nodes were snooping information about hidden services they host. We reveal that more than half of them were hosted on cloud infrastructure and delayed the use of the learned information to prevent easy traceback.