USENIX Security2017Top-tier venue
DeTor: Provably Avoiding Geographic Regions in Tor
Zhihao Li, Stephen Herwig, Dave Levin
Abstract
Large, routing-capable adversaries such as nationstates have the ability to censor and launch powerful deanonymization attacks against Tor circuits that traverse their borders. Tor allows users to specify a set of countries to exclude from circuit selection, but this provides merely the illusion of control, as it does not preclude those countries from being on the path between nodes in a circuit. For instance, we find that circuits excluding US Tor nodes definitively avoid the US 12% of the time. This paper presents DeTor, a set of techniques for proving when a Tor circuit has avoided user-specified geographic regions. DeTor extends recent work on using speed-of-light constraints to prove that a round-trip of communication physically could not have traversed certain geographic regions. As such, DeTor does not require modifications to the Tor protocol, nor does it require a map of the Internet's topology. We show how DeTor can be used to avoid censors (by never transiting the censor once) and to avoid timing-based deanonymization attacks (by never transiting a geographic region twice). We analyze DeTor's success at finding avoidance circuits through simulation using real latencies from Tor.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a3791e10-7f90-4b35-bd8c-4224dc25bb42Cited by top-tier papers7
- Geneva: Evolving Censorship Evasion StrategiesKevin Bock, George Hughey, Xiao Qiang, Dave LevinCCS 2019 · 60 citations
- CLAPS: Client-Location-Aware Path Selection in TorFlorentin Rochet, Ryan Wails, Aaron Johnson, Prateek Mittal et al.CCS 2020 · 23 citations
- On the Challenges of Geographical Avoidance for TorKatharina Kohls, Kai Jansen, David Rupprecht, Thorsten Holz et al.NDSS 2019 · 22 citations
- Bento: safely bringing network function virtualization to TorMichael Reininger, Arushi Arora, Stephen Herwig, Nicholas Francino et al.SIGCOMM 2021 · 6 citations
- VerLoc: Verifiable Localization in Decentralized SystemsKatharina Kohls, Claudia DíazUSENIX Security 2022
Related papers
- Avoiding The Man on the Wire: Improving Tor's Security with Trust-Aware Path SelectionAaron Johnson, Rob Jansen, Aaron D. Jaggard, Joan Feigenbaum et al.NDSS 2017 · 30 citations
- Duplicate-Node Attack: Identifying Guards to Degrade and Triangulate Onion ServicesChunmian Wang, Xiaodan Gu, Ming Yang, Qi Chen et al.INFOCOM 2026
- ShorTor: Improving Tor Network Latency via Multi-hop Overlay RoutingKyle Hogan, Sacha Servan-Schreiber, Zachary Newman, Ben Weintraub et al.S&P 2022 · 17 citations
- Do Not Trust What They Tell: Exposing Malicious Accomplices in Tor via Anomalous Circuit DetectionYixuan Yao, Ming Yang, Zixia Liu, Kai Dong et al.WWW 2025 · 2 citations
- GAME OF DECOYS: Optimal Decoy Routing Through Game TheoryMilad Nasr, Amir HoumansadrCCS 2016 · 25 citations
