TorWard: Discovery, Blocking, and Traceback of Malicious Traffic Over Tor

TorWard: Discovery, Blocking, and Traceback of Malicious Traffic Over Tor
复制标题

TorWard:发现、阻止和追溯 Tor 上的恶意流量

DOI:
10.1109/tifs.2015.2465934
复制
发表时间:
2015
影响因子:
6.8
通讯作者:
Zhen Ling
Zhen Ling
中科院分区:
计算机科学1区
文献类型:
--
作者:
Junzhou Luo;Kui Wu;Wei Yu;Xinwen Fu;Zhen Ling

文献摘要

相似文献

Tor 是一种流行的低延迟匿名通信系统。然而,目前它正以各种方式被滥用。 Tor 出口路由器经常受到行政和法律投诉的困扰。为了深入了解此类滥用情况,我们设计并实现了一个新颖的系统 TorWard,用于发现和系统研究 Tor 上的恶意流量。该系统可以避免法律和行政投诉,并允许调查在大学校园等敏感环境中进行。入侵检测系统 (IDS) 用于发现恶意流量并对其进行分类。我们进行了全面的分析和广泛的实际实验,以验证 TorWard 的可行性和有效性。我们的结果显示,大约 10% 的 Tor 流量可以触发 IDS 警报。恶意流量包括P2P流量、恶意软件流量(例如僵尸网络流量)、拒绝服务攻击流量、垃圾邮件等。已识别出约 200 种已知恶意软件。为了减少 Tor 的滥用,我们实施了一个防御系统,该系统可以处理 IDS 警报、拆除并阻止可疑连接。为了便于对恶意流量进行取证追踪,我们实施了一种基于双音多频信令的方法来关联 Tor 入口路由器和出口路由器的僵尸网络流量。我们进行了理论分析和广泛的实际实验,以验证 TorWard 在发现、阻止和追踪恶意流量方面的可行性和有效性。
Tor is a popular low-latency anonymous communication system. It is, however, currently abused in various ways. Tor exit routers are frequently troubled by administrative and legal complaints. To gain an insight into such abuse, we designed and implemented a novel system, TorWard, for the discovery and the systematic study of malicious traffic over Tor. The system can avoid legal and administrative complaints, and allows the investigation to be performed in a sensitive environment such as a university campus. An intrusion detection system (IDS) is used to discover and classify malicious traffic. We performed comprehensive analysis and extensive real-world experiments to validate the feasibility and the effectiveness of TorWard. Our results show that around 10% Tor traffic can trigger IDS alerts. Malicious traffic includes P2P traffic, malware traffic (e.g., botnet traffic), denial-of-service attack traffic, spam, and others. Around 200 known malwares have been identified. To mitigate the abuse of Tor, we implemented a defense system, which processes IDS alerts, tears down, and blocks suspect connections. To facilitate forensic traceback of malicious traffic, we implemented a dual-tone multi-frequency signaling-based approach to correlate botnet traffic at Tor entry routers and that at exit routers. We carried out theoretical analysis and extensive real-world experiments to validate the feasibility and the effectiveness of TorWard for discovery, blocking, and traceback of malicious traffic.