The Effect of DNS on Tor's Anonymity

The Effect of DNS on Tor's Anonymity
复制标题

DNS 对 Tor 匿名性的影响

DOI:
--
复制
发表时间:
2016
期刊:
Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
N. Feamster
N. Feamster
中科院分区:
--
文献类型:
--
作者:
Benjamin Greschbach;T. Pulls;Laura M. Roberts;Philipp Winter;N. Feamster

文献摘要

参考文献

被引文献

相似文献

以前在ToR网络中链接流量的发送方和接收方的攻击(“关联攻击”)通常依赖于分析来自TCP连接的流量。然而,典型客户端应用程序的TCP连接通常伴随着DNS请求和响应。这种额外的流量带来了更多的关联攻击机会。本文量化了DNS流量如何使ToR用户更容易受到关联攻击。我们调查了合并DNS流量如何使现有的关联攻击更加强大,以及DNS查找如何将有关匿名通信的信息泄露给第三方。我们(I)开发了一种方法来识别ToR出口中继的DNS解析器;(Ii)开发了一组新的关联攻击(逃逸攻击),其中结合了DNS流量来提高精度;(Iii)分析了这些新攻击对Tor用户的互联网规模影响;以及(Iv)开发了改进的关联攻击评估方法。首先,我们发现存在可以发动叛逃者攻击的对手:例如,Google的DNS解析器可以观察到几乎40%的退出Tor网络的DNS请求。我们还发现,DNS请求经常经过相应的TCP连接不传输的AS,从而使更多的AS能够获得有关ToR用户流量的信息。然后,我们展示了可以发动叛逃者攻击的对手通常可以完美地精确地确定Tor用户正在访问的网站,特别是对于不太受欢迎的网站,其中与该网站相关联的一组DNS名称可能是该网站唯一的。我们还使用Tor路径模拟器(TORPS)结合来自与Tor出口中继器位于同一位置的有利位置的Traceroute数据来估计在实践中可能发动叛逃者攻击的AS级对手的力量。
Previous attacks that link the sender and receiver of traffic in the Tor network ("correlation attacks") have generally relied on analyzing traffic from TCP connections. The TCP connections of a typical client application, however, are often accompanied by DNS requests and responses. This additional traffic presents more opportunities for correlation attacks. This paper quantifies how DNS traffic can make Tor users more vulnerable to correlation attacks. We investigate how incorporating DNS traffic can make existing correlation attacks more powerful and how DNS lookups can leak information to third parties about anonymous communication. We (i) develop a method to identify the DNS resolvers of Tor exit relays; (ii) develop a new set of correlation attacks (DefecTor attacks) that incorporate DNS traffic to improve precision; (iii) analyze the Internet-scale effects of these new attacks on Tor users; and (iv) develop improved methods to evaluate correlation attacks. First, we find that there exist adversaries who can mount DefecTor attacks: for example, Google's DNS resolver observes almost 40% of all DNS requests exiting the Tor network. We also find that DNS requests often traverse ASes that the corresponding TCP connections do not transit, enabling additional ASes to gain information about Tor users' traffic. We then show that an adversary who can mount a DefecTor attack can often determine the website that a Tor user is visiting with perfect precision, particularly for less popular websites where the set of DNS names associated with that website may be unique to the site. We also use the Tor Path Simulator (TorPS) in combination with traceroute data from vantage points co-located with Tor exit relays to estimate the power of AS-level adversaries who might mount DefecTor attacks in practice.
DOI: --
发表时间: 2016
期刊: --
影响因子: --
作者:
Khattak, S.
通讯作者: Khattak, S.