Large-scale Evaluation of Malicious Tor Hidden Service Directory Discovery
Chunmian Wang, Zhen Ling, Wenjia Wu, Qi Chen, Ming Yang, Xinwen Fu
摘要
Tor is the largest anonymous communication system, providing anonymous communication services to approximately 2.8 million users and 170,000 hidden services per day. The Tor hidden service mechanism can protect a server from exposing its real identity during the communication. However, due to a design flaw of the Tor hidden service mechanism, adversaries can deploy malicious Tor hidden service directories (HSDirs) to covertly collect all onion addresses of hidden services and further probe the hidden services. To mitigate this issue, we design customized honeypot hidden services based on one-to-one and many-to-one HSDir monitoring approaches to luring and identifying the malicious HSDirs conducting the rapid and delayed probing attacks, respectively. By analyzing the probing behaviors and payloads, we investigate a novel semantic-based probing pattern clustering approach to classify the adversaries so as to shed light on the purposes of the malicious HSDirs. Moreover, we perform theoretical analysis of the capability and accuracy of our approaches. Large-scale experiments are conducted in the real-world Tor network by deploying hundreds of thousands of honeypots during a monitoring period of more than three months. Finally, we identify 8 groups of 32 malicious HSDirs, discover 25 probing pattern clusters and reveal 3 major probing purposes.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper3
- Counter-RAPTOR: Safeguarding Tor Against Active Routing AttacksYixin Sun, Anne Edmundson, Nick Feamster, Mung Chiang 等S&P 2017 · 被引用 60 次
- Dissecting Tor Bridges: A Security Evaluation of their Private and Public InfrastructuresSrdjan Matic, Carmela Troncoso, Juan CaballeroNDSS 2017 · 被引用 21 次
- Characterizing the Nature and Dynamics of Tor Exit BlockingRachee Singh, Rishab Nithyanand, Sadia Afroz, Paul Pearce 等USENIX Security 2017 · 被引用 6 次
相关 Paper
- HSDirSniper: A New Attack Exploiting Vulnerabilities in Tor's Hidden Service DirectoriesQingfeng Zhang, Zhiyang Teng, Xuebin Wang, Yue Gao 等WWW 2024 · 被引用 4 次
- Do Not Trust What They Tell: Exposing Malicious Accomplices in Tor via Anomalous Circuit DetectionYixuan Yao, Ming Yang, Zixia Liu, Kai Dong 等WWW 2025 · 被引用 2 次
- Identifying and Characterizing Sybils in the Tor NetworkPhilipp Winter, Roya Ensafi, Karsten Loesing, Nick FeamsterUSENIX Security 2016 · 被引用 53 次
- A Comprehensive and Long-term Evaluation of Tor V3 Onion ServicesChunmian Wang, Junzhou Luo, Zhen Ling, Lan Luo 等INFOCOM 2023 · 被引用 8 次
- Exposing the Rat in the Tunnel: Using Traffic Analysis for Tor-based Malware DetectionPriyanka Dodia, Mashael AlSabah, Omar Alrawi, Tao WangCCS 2022 · 被引用 31 次
