Timeless Timing Attacks and Preload Defenses in Tor's DNS Cache
Rasmus Dahlberg, Tobias Pulls
摘要
We show that Tor's DNS cache is vulnerable to a timeless timing attack, allowing anyone to determine if a domain is cached or not without any false positives. The attack requires sending a single TLS record. It can be repeated to determine when a domain is no longer cached to leak the insertion time. Our evaluation in the Tor network shows no instances of cached domains being reported as uncached and vice versa after 12M repetitions while only targeting our own domains. This shifts DNS in Tor from an unreliable side-channelusing traditional timing attacks with network jitter-to being perfectly reliable. We responsibly disclosed the attack and suggested two short-term mitigations. As a long-term defense for the DNS cache in Tor against all types of (timeless) timing attacks, we propose a redesign where only an allowlist of domains is preloaded to always be cached across circuits. We compare the performance of a preloaded DNS cache to Tor's current solution towards DNS by measuring aggregated statistics for four months from two exits (after engaging with the Tor Research Safety Board and our university ethical review process). The evaluated preload lists are variants of the following top-lists: Alexa, Cisco Umbrella, and Tranco. Our results show that four-months-old preload lists can be tuned to offer comparable performance under similar resource usage or to significantly improve shared cache-hit ratios (2-3x) with a modest increase in memory usage and resolver load compared to a 100 Mbit/s exit. We conclude that Tor's current DNS cache is mostly a privacy harm because the majority of cached domains are unlikely to lead to cache hits but remain there to be probed by attackers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper11
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- DeepCorr: Strong Flow Correlation Attacks on Tor Using Deep LearningMilad Nasr, Alireza Bahramali, Amir HoumansadrCCS 2018 · 被引用 187 次
- Anonymity Trilemma: Strong Anonymity, Low Bandwidth Overhead, Low Latency - Choose TwoDebajyoti Das, Sebastian Meiser, Esfandiar Mohammadi, Aniket KateS&P 2018 · 被引用 99 次
- Safely Measuring TorRob Jansen, Aaron JohnsonCCS 2016 · 被引用 76 次
- The Effect of DNS on Tor's AnonymityBenjamin Greschbach, Tobias Pulls, Laura M. Roberts, Philipp Winter 等NDSS 2017 · 被引用 51 次
相关 Paper
- A Flushing Attack on the DNS CacheYehuda Afek, Anat Bremler-Barr, Shoham Danino, Yuval ShavittUSENIX Security 2024 · 被引用 2 次
- Continuous User Behavior Monitoring using DNS Cache Timing AttacksHannes Weissteiner, Roland Czerny, Simone Franza, Stefan Gast 等NDSS 2026 · 被引用 2 次
- DNS FLaRE: A Flush-Reload Attack on DNS ForwardersGilad Moav, Yehuda Afek, Anat Bremler-Barr, Amit KleinUSENIX Security 2025
- Cached and Confused: Web Cache Deception in the WildSeyed Ali Mirheidari, Sajjad Arshad, Kaan Onarlioglu, Bruno Crispo 等USENIX Security 2020
- Targeted Deanonymization via the Cache Side Channel: Attacks and DefensesMojtaba Zaheri, Yossi Oren, Reza CurtmolaUSENIX Security 2022
