Five Minutes of DDoS Brings down Tor: DDoS Attacks on the Tor Directory Protocol and Mitigations
Zhongtang Luo, Jianting Zhang, Akshat Neerati, Aniket Kate
Abstract
The Tor network offers network anonymity to its users by routing their traffic through a sequence of relays. A group of nine directory authorities maintains information about all available relay nodes using a distributed directory protocol. We observe that the current protocol makes a strong synchrony assumption, which makes it vulnerable to natural as well as adversarial non-synchronous communication scenarios over the Internet. In this paper, we show that it is possible to cause a failure in the Tor directory protocol by targeting a majority of the authorities for only five minutes using a well-executed distributed denial-of-service (DDoS) attack. We demonstrate this attack in a controlled environment and show that it is cost-effective for as little as $53.28 per month to disrupt the protocol and to effectively bring down the entire Tor network. To mitigate this problem, we consider the popular partial synchrony assumption that ensures protocol security even when the network delays are large and unknown initially. We design a new Tor directory protocol that leverages a standard partial-synchronous consensus protocol to solve this problem, while also proving its security. We have implemented a prototype in Rust, demonstrating comparable performance to the current protocol.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e9d87170-c7ea-4e2a-9c64-1dddc6d1934bBuilds on12
- Routing Around Congestion: Defeating DDoS Attacks and Adverse Network Conditions via Reactive BGP RoutingJared M. Smith, Max SchuchardS&P 2018 · 71 citations
- Identifying and Characterizing Sybils in the Tor NetworkPhilipp Winter, Roya Ensafi, Karsten Loesing, Nick FeamsterUSENIX Security 2016 · 53 citations
- United We Stand: Collaborative Detection and Mitigation of Amplification DDoS Attacks at ScaleDaniel Wagner, Daniel Kopp, Matthias Wichtlhuber, Christoph Dietzel et al.CCS 2021 · 50 citations
- Point Break: A Study of Bandwidth Denial-of-Service Attacks against TorRob Jansen, Tavish Vaidya, Micah SherrUSENIX Security 2019 · 49 citations
- FIN: Practical Signature-Free Asynchronous Common Subset in Constant TimeSisi Duan, Xin Wang, Haibin ZhangCCS 2023 · 45 citations
Related papers
- Attacking and Improving the Tor Directory ProtocolZhongtang Luo, Adithya Bhat, Kartik Nayak, Aniket KateS&P 2024 · 5 citations
- Descriptors of Exposure: Undermining Tor Anonymity Through Exploiting Descriptor FloodChunmian Wang, Junzhou Luo, Zhen Ling, Yue Zhang et al.S&P 2026
- Onions Got Puzzled: On the Challenges of Mitigating Denial-of-Service Problems in Tor Onion ServicesJinseo Lee, Hobin Kim, Min Suk KangUSENIX Security 2025
- HSDirSniper: A New Attack Exploiting Vulnerabilities in Tor's Hidden Service DirectoriesQingfeng Zhang, Zhiyang Teng, Xuebin Wang, Yue Gao et al.WWW 2024 · 4 citations
- Duplicate-Node Attack: Identifying Guards to Degrade and Triangulate Onion ServicesChunmian Wang, Xiaodan Gu, Ming Yang, Qi Chen et al.INFOCOM 2026
