How to block Tor’s hidden bridges: detecting methods and countermeasures

How to block Tor’s hidden bridges: detecting methods and countermeasures
复制标题

DOI:
10.1007/s11227-012-0788-4
复制
发表时间:
2013-12
期刊:
The Journal of Supercomputing
影响因子:
--
通讯作者:
Ming Yang;Junzhou Luo;Lu Zhang;Xiaogang Wang;Xinwen Fu
Ming Yang;Junzhou Luo;Lu Zhang;Xiaogang Wang;Xinwen Fu
中科院分区:
其他
文献类型:
--
作者:
Ming Yang;Junzhou Luo;Lu Zhang;Xiaogang Wang;Xinwen Fu

文献摘要

相似文献

Tor网络已被广泛用于保护用户在访问各种在线服务时的隐私。由于Tor可以通过将公开发布的Tor中继列入黑名单来轻松阻止,因此在当前的Tor网络中设计并实现了基于隐藏桥的阻止机制。任何用户都可以通过电子邮件,https,twitter等订阅一个元组的三个桥梁,但是,我们发现,这些公布的元组之间存在很高的相关性,可以利用它来有效地检测隐藏的桥梁,通过监控从受控网络的出站流量。当Tor客户端尝试连接选定的隐藏网桥时,具有连续源端口的多个SYN数据包将几乎同时发送,目的地为不同的主机。如果这些数据包中包含的任何目的IP属于已知的网桥,则可以推断所有其他目的IP也属于网桥。通过记录和分析一系列满足上述分组特征的业务段,可以检测并进一步阻断受控网络中使用的隐藏网桥。根据不同的可用计算和存储资源,我们提出了在线和离线检测方法。分析和仿真结果都验证了已发表的桥元组之间的高度相关性,验证了我们的方法的可行性。通过配置优化的检测参数,在线检测的检测率为86.7%,假阳性率为0.85%,离线检测的检测率为98.4%,假阳性率为0.62%.针对Tor现有的抗阻塞机制存在的缺陷,分别从Tor网络和用户的角度提出了相应的对策。
Tor network has been widely used for protecting the privacy of users while accessing various online services. Since Tor can be easily blocked by blacklisting the publicly published Tor relays, the hidden bridges-based blocking-resistance mechanism is designed and implemented in the current Tor network. Any user can subscribe a tuple of three bridges via email, https, twitter etc. However, we have found that there exist high correlations among those published tuples, which can be exploited to effectively detect hidden bridges by monitoring the outbound traffic from a controlled network. When Tor clients try to connect chosen hidden bridges, multiple SYN packets with consecutive source ports will be sent almost simultaneously, destining for different hosts. If any destination IP contained among such packets belongs to a known bridge, all others can then be inferred to be of bridges too. By recording and analyzing a series of traffic segments satisfying the above packet features, the hidden bridges used in a controlled network can be detected and further blocked. According to different available computing and storage resources, we proposed both online and offline detecting methods. Both analytical and simulation results verify the high correlation among published bridge tuples, validating the feasibility of our methods. By configuring optimized detecting parameters in the real-world experiments, we can achieve a detection rate of 86.7 % with a 0.85 % false-positive rate for online detection, and a 98.4 % detection rate with a 0.62 % false-positive rate for offline detection. To make up the flaws in Tor’s current blocking-resistance mechanism, we also provide some countermeasures from the perspective of Tor network and users, respectively.