Dissecting Tor Bridges: A Security Evaluation of their Private and Public Infrastructures
Srdjan Matic, Carmela Troncoso, Juan Caballero
摘要
Bridges are onion routers in the Tor Network whose IP addresses are not public. So far, no global security analysis of Tor bridges has been performed. Leveraging public data sources, and two known Tor issues, we perform the first systematic study on the security of the Tor bridges infrastructure. Our study covers both the public infrastructure available to all Tor users, and the previously unreported private infrastructure, comprising private nodes for the exclusive use of those who know their existence. Our analysis of the public infrastructure is twofold. First, we examine the security implications of the public data in the CollecTor service, identifying several pieces of data that may be detrimental for the security of bridges. Then, we measure security relevant properties of public bridges. Our results show that the 55% of public bridges that carry clients are vulnerable to aggressive blocking; that 90% of bridge clients use default bridges that are trivial to identify; that the concurrent deployment of Pluggable Transports in bridges reduces the security of the most secure transports; and that running non-Tor services in the same host as a bridge may harm its anonymity. To study the private infrastructure, we use an approach to discover 694 private bridges on the Internet and a novel technique to track bridges across IP changes. We are first to measure the size of the private bridge population (35% discovered bridges are private) and to report existence of infrastructures that use private proxies to forward traffic to backend bridges or relays. We use a novel clustering approach to analyze the different infrastructures using proxies and bridges, examining its hosting and security properties. We provide an extensive discussion on the security implications of our findings. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Point Break: A Study of Bandwidth Denial-of-Service Attacks against TorRob Jansen, Tavish Vaidya, Micah SherrUSENIX Security 2019 · 被引用 49 次
- You Shall Not Join: A Measurement Study of Cryptocurrency Peer-to-Peer Bootstrapping TechniquesAngelique Faye Loe, Elizabeth Anne QuagliaCCS 2019 · 被引用 19 次
- Large-scale Evaluation of Malicious Tor Hidden Service Directory DiscoveryChunmian Wang, Zhen Ling, Wenjia Wu, Qi Chen 等INFOCOM 2022 · 被引用 10 次
它引用的顶会 Paper2
相关 Paper
- Do Not Trust What They Tell: Exposing Malicious Accomplices in Tor via Anomalous Circuit DetectionYixuan Yao, Ming Yang, Zixia Liu, Kai Dong 等WWW 2025 · 被引用 2 次
- Bypassing Tor Exit Blocking with Exit Bridge Onion ServicesZhao Zhang, Wenchao Zhou, Micah SherrCCS 2020 · 被引用 8 次
- How Do Tor Users Interact With Onion Services?Philipp Winter, Anne Edmundson, Laura M. Roberts, Agnieszka Dutkowska-Zuk 等USENIX Security 2018 · 被引用 42 次
- Inside Job: Applying Traffic Analysis to Measure Tor from WithinRob Jansen, Marc Juarez, Rafa Gálvez, Tariq Elahi 等NDSS 2018 · 被引用 86 次
- Do You See What I See? Differential Treatment of Anonymous UsersSheharbano Khattak, David Fifield, Sadia Afroz, Mobin Javed 等NDSS 2016 · 被引用 77 次
