Bento: safely bringing network function virtualization to Tor
Michael Reininger, Arushi Arora, Stephen Herwig, Nicholas Francino, Jayson Hurst, Christina Garman, Dave Levin
Abstract
Tor is a powerful and important tool for providing anonymity and censorship resistance to users around the world. Yet it is surprisingly difficult to deploy new services in Tor-it is largely relegated to proxies and hidden services-or to nimbly react to new forms of attack. Conversely, "non-anonymous" Internet services are thriving like never before because of recent advances in programmable networks, such as Network Function Virtualization (NFV) which provides programmable in-network middleboxes.
This paper seeks to close this gap by introducing programmable middleboxes into the Tor network. In this architecture, users can install and run sophisticated "functions" on willing Tor routers. We demonstrate a wide range of functions that improve anonymity, resilience to attack, performance of hidden services, and more. We present the design and implementation of an architecture, Bento, that protects middlebox nodes from the functions they run-and protects the functions from the middleboxes they run on.
Bento does not require modifications to Tor, and we evaluate it by running it on the live Tor network. We show that, with just a few lines of Python, we can significantly extend the capabilities of Tor to meet users' anonymity needs and nimbly react to new threats.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dd5c8698-18ae-4a65-a4bb-ca50f4bfa502Cited by top-tier papers1
Ask how each one uses itBuilds on8
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 632 citations
- Walkie-Talkie: An Efficient Defense Against Passive Website Fingerprinting AttacksTao Wang, Ian GoldbergUSENIX Security 2017 · 249 citations
- OBLIVIATE: A Data Oblivious Filesystem for Intel SGXAdil Ahmad, Kyungtae Kim, Muhammad Ihsanulhaq Sarfaraz, Byoungyoung LeeNDSS 2018 · 144 citations
- Anonymity Trilemma: Strong Anonymity, Low Bandwidth Overhead, Low Latency - Choose TwoDebajyoti Das, Sebastian Meiser, Esfandiar Mohammadi, Aniket KateS&P 2018 · 99 citations
Related papers
- Do Not Trust What They Tell: Exposing Malicious Accomplices in Tor via Anomalous Circuit DetectionYixuan Yao, Ming Yang, Zixia Liu, Kai Dong et al.WWW 2025 · 2 citations
- MUFFLER: Secure Tor Traffic Obfuscation with Dynamic Connection Shuffling and SplittingMinjae Seo, Myoungsung You, Jaehan Kim, Taejune Park et al.INFOCOM 2025
- ShorTor: Improving Tor Network Latency via Multi-hop Overlay RoutingKyle Hogan, Sacha Servan-Schreiber, Zachary Newman, Ben Weintraub et al.S&P 2022 · 17 citations
- Flow Correlation Attacks on Tor Onion Service Sessions with Sliding Subset SumDaniela Lopes, Jin-Dong Dong, Pedro Medeiros, Daniel Castro et al.NDSS 2024
- Bypassing Tor Exit Blocking with Exit Bridge Onion ServicesZhao Zhang, Wenchao Zhou, Micah SherrCCS 2020 · 8 citations
