Exposing the Rat in the Tunnel: Using Traffic Analysis for Tor-based Malware Detection
Priyanka Dodia, Mashael AlSabah, Omar Alrawi, Tao Wang
Abstract
Tor [31] is the most widely used anonymous communication network with millions of daily users [6]. Since Tor provides server and client anonymity, hundreds of malware binaries found in the wild rely on it to hide their presence and hinder Command & Control (C&C) takedown operations. We believe Tor is a paramount tool enabling online freedom and privacy, and blocking it to defend against such malware is infeasible for both users and organizations. In this work, we present effective traffic analysis approaches that can accurately identify Tor-based malware communication. We collect hundreds of Tor-based malware binaries, execute and examine more than 47,000 active encrypted malware connections and compare them with benign browsing traffic. In addition to traditional traffic analysis features (which work at the connection level), we propose global host-level network features to capture peculiar malware communication fingerprints across host logs. Our experiments confirm that our models are able to detect "zero-day" malware connections with 0.7% FPR even when malware connections constitute less than 5% of Tor traces in the test set. Using multi-labeling approaches, we are able to accurately detect the malware behavior-based classes (grayware, ransomware, etc). Finally, we evaluate the robustness of our models on real-world enterprise logs and show that the classifiers can identify infected hosts even with missing features. CCS CONCEPTS • Security and privacy → Malware and its mitigation; Privacypreserving protocols.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 39f94f4f-ce2c-46a2-8d62-3bec36cfb092Cited by top-tier papers11
- Point Cloud Analysis for ML-Based Malicious Traffic Detection: Reducing Majorities of False Positive AlarmsChuanpu Fu, Qi Li, Ke Xu, Jianping WuCCS 2023 · 30 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Detecting Tunneled Flooding Traffic via Deep Semantic Analysis of Packet Length PatternsChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2024 · 13 citations
- In Search of netUnicorn: A Data-Collection Platform to Develop Generalizable ML Models for Network Security ProblemsRoman Beltiukov, Wenbo Guo, Arpit Gupta, Walter WillingerCCS 2023 · 10 citations
- A Hard-Label Black-Box Evasion Attack against ML-based Malicious Traffic Detection SystemsZixuan Liu, Yi Zhao, Zhuotao Liu, Qi Li et al.NDSS 2026 · 3 citations
Builds on6
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 632 citations
- Triplet Fingerprinting: More Practical and Portable Website Fingerprinting with N-shot LearningPayap Sirinam, Nate Mathews, Mohammad Saidur Rahman, Matthew WrightCCS 2019 · 268 citations
- Beauty and the Burst: Remote Identification of Encrypted Video StreamsRoei Schuster, Vitaly Shmatikov, Eran TromerUSENIX Security 2017 · 205 citations
- The Circle Of Life: A Large-Scale Study of The IoT Malware LifecycleOmar Alrawi, Charles Lever, Kevin Valakuzhy, Ryan Court et al.USENIX Security 2021 · 109 citations
- Forecasting Malware Capabilities From Cyber Attack Memory ImagesOmar Alrawi, Moses Ike, Matthew Pruett, Ranjita Pai Kasturi et al.USENIX Security 2021 · 32 citations
Related papers
- Fingerprinting the Shadows: Unmasking Malicious Servers with Machine Learning-Powered TLS AnalysisAndreas Theofanous, Eva Papadogiannaki, Alexander Shevtsov, Sotiris IoannidisWWW 2024 · 7 citations
- Transformer-based Model for Multi-tab Website Fingerprinting AttackZhaoxin Jin, Tianbo Lu, Shuang Luo, Jiaze ShangCCS 2023 · 30 citations
- Large-scale Evaluation of Malicious Tor Hidden Service Directory DiscoveryChunmian Wang, Zhen Ling, Wenjia Wu, Qi Chen et al.INFOCOM 2022 · 10 citations
- Subverting Website Fingerprinting Defenses with Robust Traffic RepresentationMeng Shen, Kexin Ji, Zhenbo Gao, Qi Li et al.USENIX Security 2023
- Do Not Trust What They Tell: Exposing Malicious Accomplices in Tor via Anomalous Circuit DetectionYixuan Yao, Ming Yang, Zixia Liu, Kai Dong et al.WWW 2025 · 2 citations
