Descriptors of Exposure: Undermining Tor Anonymity Through Exploiting Descriptor Flood
Chunmian Wang, Junzhou Luo, Zhen Ling, Yue Zhang, Shan Wang, Ming Yang, Guangchi Liu, Xinwen Fu
Abstract
Tor is a widely used network for anonymous communication, employing onion encryption and multi-hop routing to ensure anonymity for its users and service providers. Despite its robust design, Tor has been the target of numerous attacks, such as denial-of-service (DoS) attacks and deanonymization attacks. However, these attacks often rely on resource-intensive methods, such as bandwidth inflation or controlling large-scale nodes. They face limitations due to high costs, limited scalability, and countermeasures that Tor already has in place. In this paper, we identify a new vulnerability, termed the Descriptor Flood, in Tor's memory management mechanism and service publication protocol. By exploiting Descriptor Flood, attackers can flood Tor nodes with malicious descriptors of onion services, causing severe memory fragmentation, exhaustion, and eventual node crash. Unlike conventional attacks, our method leverages a fundamental design flaw, allowing cost-effective and scalable exploitation without requiring substantial resources. To demonstrate the practical impact of this vulnerability, we propose the Tordos Attack, a three-phase strategy that efficiently disables Tor nodes and executes DoS and deanonymization attacks against onion services via tearing down specific nodes in Tor. The attack addresses key challenges, such as measuring node memory capacity, inducing fragmentation, and disabling critical nodes to maximize disruption. Our extensive experimental results indicate that the attack can disable Tor nodes and onion services within 9.1 minutes and expose the onion service's real identity in 6.1 hours, potentially leading to the collapse of the entire Tor network.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 5d9a290f-1f7d-4019-9082-9251eba51438Related papers
- Duplicate-Node Attack: Identifying Guards to Degrade and Triangulate Onion ServicesChunmian Wang, Xiaodan Gu, Ming Yang, Qi Chen et al.INFOCOM 2026
- Point Break: A Study of Bandwidth Denial-of-Service Attacks against TorRob Jansen, Tavish Vaidya, Micah SherrUSENIX Security 2019 · 49 citations
- Onions Got Puzzled: On the Challenges of Mitigating Denial-of-Service Problems in Tor Onion ServicesJinseo Lee, Hobin Kim, Min Suk KangUSENIX Security 2025
- MirageFlow: A New Bandwidth Inflation Attack on TorChristoph Sendner, Jasper Stang, Alexandra Dmitrienko, Raveen Wijewickrama et al.NDSS 2024
- Five Minutes of DDoS Brings down Tor: DDoS Attacks on the Tor Directory Protocol and MitigationsZhongtang Luo, Jianting Zhang, Akshat Neerati, Aniket KateEuroSys 2026
