稳定性的代价:去匿名化洋葱服务长期存在的引入电路
The Cost of Stability: Deanonymizing Onion Services Long-Lived Introduction Circuits
查看机构详情
- KU Leuven(荷语鲁汶大学)
机构由 AI 辅助整理,请以论文原文为准。
浏览论文内容
中文总结 AI 辅助
本文针对Tor洋葱服务长期固定的引入电路,提出交集攻击,通过逐个观察中继识别服务位置,实验显示中位2.2小时可重建完整电路,并提出定期重建电路的缓解机制。
中文摘要 AI 辅助
Tor是一个广泛使用的匿名网络,通过将客户端通信经由一系列中继路由到目的地来提供网络隐私。观察单个Tor中继的对手无法轻易将客户端与其目的地关联起来,因为这样做需要识别客户端电路上的其他中继。仅从被监控的中继所观察到的流量中识别这些中继具有挑战性:每个中继同时承载许多电路的流量,且客户端电路通常仅持续约10分钟,限制了对给定电路的观察。相比之下,Tor洋葱服务使用引入电路,这些电路保持固定18至24小时。我们开发了一种交集攻击,利用这一设计,使自适应对手能够一次观察一个Tor中继,从而识别洋葱服务的网络位置。我们在实时Tor网络上针对一个承载真实第三方流量的自营洋葱服务评估了该攻击。在九次端到端实验中,该攻击在每次运行中都重建了完整的Tor电路,估计中位时间为2.2小时。为缓解此攻击,我们提出了一种机制,定期重建内部引入电路以限制证据积累,而不改变公开宣传的信息。
英文摘要
Tor is a widely used anonymity network that provides network privacy by routing client communications through a sequence of relays to their destinations. An adversary observing a single Tor relay cannot readily link clients to their destinations, as doing so requires identifying the other relays along the client circuit. Identifying these relays from traffic observed at the monitored relay alone is challenging: each relay carries traffic for many circuits simultaneously, and client circuits typically last only about 10 min, limiting observations of a given circuit. In contrast, Tor onion services use introduction circuits that remain fixed for 18 to 24 h. We develop an intersection attack that exploits this design, allowing an adaptive adversary observing one Tor relay at a time to identify the network location of an onion service. We evaluate the attack on the live Tor network against a self-operated onion service carrying genuine third-party traffic. Across nine end-to-end experiments, the attack reconstructs the complete Tor circuit in every run, with an estimated median time of 2.2 h. To mitigate this attack, we propose a mechanism that periodically rebuilds internal introduction circuits to limit evidence accumulation without changing publicly advertised information.