Duplicate-Node Attack: Identifying Guards to Degrade and Triangulate Onion Services
Chunmian Wang, Xiaodan Gu, Ming Yang, Qi Chen, Zhou Xu
Abstract
Tor is a widely used network for anonymous communication, designed to safeguard the privacy and anonymity of both users and service providers through multi-layered encryption and multi-hop routing. Despite its robust architecture, Tor remains susceptible to various attacks, including denial-of-service (DoS) and deanonymization. However, these attacks are constrained by high resource requirements, scalability limitations, and the defenses implemented within the Tor network. Furthermore, they are particularly ineffective in identifying and circumventing the Guard nodes that protect onion services. In this paper, we uncover a novel vulnerability in Tor’s circuit construction process and bandwidth scheduling, termed the Circuit Circle vulnerability. Exploiting this flaw, attackers can create circular circuits, leading to bandwidth contention and overloading a Tor node. To demonstrate the severity of this vulnerability, we propose Duplicate-Node Attack, a three-phase strategy that identifies Guard nodes, exhausts their bandwidth, and performs coarse geolocation inference of onion services. Unlike conventional methods, our Guard node identification technique bypasses existing Tor Vanguard defenses without requiring control over any relays. Our extensive experimental results confirm that Duplicate-Node Attack can reliably identify Guard nodes, exhaust their bandwidth with minimal cost, and infer the geolocation of onion services, with an average latency bias of 35.4 ms.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 71d00b06-398f-405b-adc4-7d68b405433eRelated papers
- Descriptors of Exposure: Undermining Tor Anonymity Through Exploiting Descriptor FloodChunmian Wang, Junzhou Luo, Zhen Ling, Yue Zhang et al.S&P 2026
- Do Not Trust What They Tell: Exposing Malicious Accomplices in Tor via Anomalous Circuit DetectionYixuan Yao, Ming Yang, Zixia Liu, Kai Dong et al.WWW 2025 · 2 citations
- Point Break: A Study of Bandwidth Denial-of-Service Attacks against TorRob Jansen, Tavish Vaidya, Micah SherrUSENIX Security 2019 · 49 citations
- DeTor: Provably Avoiding Geographic Regions in TorZhihao Li, Stephen Herwig, Dave LevinUSENIX Security 2017 · 18 citations
- MirageFlow: A New Bandwidth Inflation Attack on TorChristoph Sendner, Jasper Stang, Alexandra Dmitrienko, Raveen Wijewickrama et al.NDSS 2024
