Zur Hauptnavigation wechseln Zur Suche wechseln Zum Hauptinhalt wechseln

An Extended View on Measuring Tor AS-level Adversaries

Veröffentlichungen: Beitrag in FachzeitschriftArtikelPeer Reviewed

Abstract

Tor provides anonymity to millions of users around the globe which has made it a valuable target for malicious actors. As a low-latency anonymity system, it is vulnerable to traffic correlation attacks from strong passive adversaries such as large autonomous systems (ASes). In preliminary work Mayer et al.(2020), we have developed a measurement approach utilizing the RIPE Atlas framework – a network of more than 11,000 probes worldwide – to infer the risk of deanonymization for IPv4 clients in Germany and the US.

In this paper, we apply our methodology to additional scenarios providing a broader picture of the potential for deanonymization in the Tor network. In particular, we (a) repeat our earlier (2020) measurements in 2022 to observe changes over time, (b) adopt our approach for IPv6 to analyze the risk of deanonymization when using this next-generation Internet protocol, and (c) investigate the current situation in Russia, where censorship has been intensified after the beginning of Russia’s full-scale invasion of Ukraine. According to our results, Tor provides user anonymity at consistent quality: While individual numbers vary in dependence of client and destination, we were able to identify ASes with the potential to conduct deanonymization attacks. For clients in Germany and the US, the overall picture, however, has not changed since 2020. In addition, the protocols (IPv4 vs. IPv6) do not significantly impact the risk of deanonymization. Russian users are able to securely evade censorship using Tor. Their general risk of deanonymization is, in fact, lower than in the other investigated countries. Beyond, the few ASes with the potential to successfully perform deanonymization are operated by Western companies, further reducing the risk for Russian users.
OriginalspracheEnglisch
Aufsatznummer103302
Seitenumfang14
FachzeitschriftComputers & Security
Jahrgang132
DOIs
PublikationsstatusVeröffentlicht - 1 Sept. 2023

Fördermittel

We want to thank David Schmidt for his preliminary work on this topic. This material is based upon work partially supported by (1) the Christian-Doppler-Laboratory for Security and Quality Improvement in the Production System Lifecycle; the financial support by the Austrian Federal Ministry for Digital and Economic Affairs, the National Foundation for Research, Technology and Development and the Christian Doppler Research Association are gratefully acknowledged; (2) SBA Research (SBA-K1), a COMET Centre within the framework of COMET \u2013 Competence Centers for Excellent Technologies Programme and funded by BMK, BMDW, and the province of Vienna. The COMET Programme is managed by FFG; (3) Project 877110 2big2fail funded by the Program \u201CBRIDGE1\u201D (FFG); (4) Project DynAISEC FO999887504 funded by the Program \u201CICT of the Future\u201D \u2013 an initiative of the Austrian Ministry of Climate Action, Environment, Energy, Mobility, Innovation and Technology.

ÖFOS 2012

  • 102015 Informationssysteme
  • 102016 IT-Sicherheit

Fingerprint

Untersuchen Sie die Forschungsthemen von „An Extended View on Measuring Tor AS-level Adversaries“. Zusammen bilden sie einen einzigartigen Fingerprint.

Zitationsweisen