USENIX Security2025Top-tier venue
TORCHLIGHT: Shedding LIGHT on Real-World Attacks on Cloudless IoT Devices Concealed within the Tor Network
Yumingzhi Pan, Zhen Ling, Yue Zhang, Hongze Wang, Guangchi Liu, Junzhou Luo, Xinwen Fu
Abstract
The rapidly expanding Internet of Things (IoT) landscape is shifting toward cloudless architectures, removing reliance on centralized cloud services but exposing devices directly to the internet and increasing their vulnerability to cyberattacks. Our research revealed an unexpected pattern of substantial Tor network traffic targeting cloudless IoT devices. suggesting that attackers are using Tor to anonymously exploit undisclosed vulnerabilities (possibly obtained from underground markets). To delve deeper into this phenomenon, we developed TORCHLIGHT, a tool designed to detect both known and unknown threats targeting cloudless IoT devices by analyzing Tor traffic. TORCHLIGHT filters traffic via specific IP patterns, strategically deploys virtual private server (VPS) nodes for cost-effective detection, and uses a chain-of-thought (CoT) process with large language models (LLMs) for accurate threat identification. Our results are significant: for the first time, we have demonstrated that attackers are indeed using Tor to conceal their identities while targeting cloudless IoT devices. Over a period of 12 months, TORCHLIGHT analyzed 26 TB of traffic, revealing 45 vulnerabilities, including 29 zero-day exploits with 25 CVE-IDs assigned (5 CRITICAL, 3 HIGH, 16 MEDIUM, and 1 LOW) and an estimated value of approximately $312,000. These vulnerabilities affect around 12.71 million devices across 148 countries, exposing them to severe risks such as information disclosure, authentication bypass, and arbitrary command execution. The findings have attracted significant attention, sparking widespread discussion in cybersecurity circles, reaching the top 25 on Hacker News, and generating over 190,000 views.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext efd022e2-2c55-49f4-a30d-c02b51ca7fcfBuilds on10
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Retrieval-Augmented Generation for Knowledge-Intensive NLP TasksPatrick Lewis, Ethan Perez, Aleksandra Piktus, Fabio Petroni et al.NeurIPS 2020 · 19,162 citations
- Kitsune: An Ensemble of Autoencoders for Online Network Intrusion DetectionYisroel Mirsky, Tomer Doitshman, Yuval Elovici, Asaf ShabtaiNDSS 2018 · 945 citations
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 632 citations
- Acquisitional Rule-based Engine for Discovering Internet-of-Thing DevicesXuan Feng, Qiang Li, Haining Wang, Limin SunUSENIX Security 2018 · 139 citations
Related papers
- Understanding and Securing Device Vulnerabilities through Automated Bug Report AnalysisXuan Feng, Xiaojing Liao, XiaoFeng Wang, Haining Wang et al.USENIX Security 2019 · 46 citations
- Game of Hide-and-Seek: Exposing Hidden Interfaces in Embedded Web Applications of IoT DevicesWei Xie, Jiongyi Chen, Zhenhua Wang, Chao Feng et al.WWW 2022 · 26 citations
- Identifying and Characterizing Sybils in the Tor NetworkPhilipp Winter, Roya Ensafi, Karsten Loesing, Nick FeamsterUSENIX Security 2016 · 53 citations
- Descriptors of Exposure: Undermining Tor Anonymity Through Exploiting Descriptor FloodChunmian Wang, Junzhou Luo, Zhen Ling, Yue Zhang et al.S&P 2026
- FalconScope: Effective and Efficient Detection of Hidden Web Interfaces in IoT DevicesJiaming Guo, Haoran Yang, Kuihao Yan, Jiekang Hu et al.WWW 2026
