On the Challenges of Geographical Avoidance for Tor
Katharina Kohls, Kai Jansen, David Rupprecht, Thorsten Holz, Christina Pöpper
Abstract
Traffic-analysis attacks are a persisting threat for Tor users. When censors or law enforcement agencies try to identify users, they conduct traffic-confirmation attacks and monitor encrypted transmissions to extract metadata-in combination with routing attacks, these attacks become sufficiently powerful to de-anonymize users. While traffic-analysis attacks are hard to detect and expensive to counter in practice, geographical avoidance provides an option to reject circuits that might be routed through an untrusted area. Unfortunately, recently proposed solutions introduce severe security issues by imprudent design decisions. In this paper, we approach geographical avoidance starting from a thorough assessment of its challenges. These challenges serve as the foundation for the design of an empirical avoidance concept that considers actual transmission characteristics for justified decisions. Furthermore, we address the problems of untrusted or intransparent ground truth information that hinder a reliable assessment of circuits. Taking these features into account, we conduct an empirical simulation study and compare the performance of our novel avoidance concept with existing approaches. Our results show that we outperform existing systems by 22 % fewer rejected circuits, which reduces the collateral damage of overly restrictive avoidance decisions. In a second evaluation step, we extend our initial system concept and implement the prototype TrilateraTor. This prototype is the first to satisfy the requirements of a practical deployment, as it maintains Tor's original level of security, provides reasonable performance, and overcomes the fundamental security flaws of existing systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 827826eb-756a-4fdd-9c0a-fb3c01b28d9eCited by top-tier papers5
- CLAPS: Client-Location-Aware Path Selection in TorFlorentin Rochet, Ryan Wails, Aaron Johnson, Prateek Mittal et al.CCS 2020 · 23 citations
- ShorTor: Improving Tor Network Latency via Multi-hop Overlay RoutingKyle Hogan, Sacha Servan-Schreiber, Zachary Newman, Ben Weintraub et al.S&P 2022 · 17 citations
- Bento: safely bringing network function virtualization to TorMichael Reininger, Arushi Arora, Stephen Herwig, Nicholas Francino et al.SIGCOMM 2021 · 6 citations
- VerLoc: Verifiable Localization in Decentralized SystemsKatharina Kohls, Claudia DíazUSENIX Security 2022
- Flow Correlation Attacks on Tor Onion Service Sessions with Sliding Subset SumDaniela Lopes, Jin-Dong Dong, Pedro Medeiros, Daniel Castro et al.NDSS 2024
Builds on4
- Crowd-GPS-Sec: Leveraging Crowdsourcing to Detect and Localize GPS Spoofing AttacksKai Jansen, Matthias Schäfer, Daniel Moser, Vincent Lenders et al.S&P 2018 · 135 citations
- Inside Job: Applying Traffic Analysis to Measure Tor from WithinRob Jansen, Marc Juarez, Rafa Gálvez, Tariq Elahi et al.NDSS 2018 · 86 citations
- Measuring and Mitigating AS-level Adversaries Against TorRishab Nithyanand, Oleksii Starov, Phillipa Gill, Adva Zair et al.NDSS 2016 · 79 citations
- DeTor: Provably Avoiding Geographic Regions in TorZhihao Li, Stephen Herwig, Dave LevinUSENIX Security 2017 · 18 citations
Related papers
- Avoiding The Man on the Wire: Improving Tor's Security with Trust-Aware Path SelectionAaron Johnson, Rob Jansen, Aaron D. Jaggard, Joan Feigenbaum et al.NDSS 2017 · 30 citations
- Do Not Trust What They Tell: Exposing Malicious Accomplices in Tor via Anomalous Circuit DetectionYixuan Yao, Ming Yang, Zixia Liu, Kai Dong et al.WWW 2025 · 2 citations
- Duplicate-Node Attack: Identifying Guards to Degrade and Triangulate Onion ServicesChunmian Wang, Xiaodan Gu, Ming Yang, Qi Chen et al.INFOCOM 2026
- GAME OF DECOYS: Optimal Decoy Routing Through Game TheoryMilad Nasr, Amir HoumansadrCCS 2016 · 25 citations
- TrafficSliver: Fighting Website Fingerprinting Attacks with Traffic SplittingWladimir De la Cadena, Asya Mitseva, Jens Hiller, Jan Pennekamp et al.CCS 2020 · 110 citations
