The Experts below are selected from a list of 9387 Experts worldwide ranked by ideXlab platform
Michalis Polychronakis - One of the best experts on this subject based on the ideXlab platform.
-
Measuring I2P Censorship at a Global Scale
arXiv: Computers and Society, 2019Co-Authors: Nguyen Phong Hoang, Sadie Doreen, Michalis PolychronakisAbstract:The prevalence of Internet censorship has prompted the creation of several measurement platforms for monitoring filtering activities. An important challenge faced by these platforms revolves around the trade-off between depth of measurement and breadth of coverage. In this paper, we present an opportunistic censorship measurement infrastructure built on top of a Network of distributed VPN servers run by volunteers, which we used to measure the extent to which the I2P Anonymity Network is blocked around the world. This infrastructure provides us with not only numerous and geographically diverse vantage points, but also the ability to conduct in-depth measurements across all levels of the Network stack. Using this infrastructure, we measured at a global scale the availability of four different I2P services: the official homepage, its mirror site, reseed servers, and active relays in the Network. Within a period of one month, we conducted a total of 54K measurements from 1.7K Network locations in 164 countries. With different techniques for detecting domain name blocking, Network packet injection, and block pages, we discovered I2P censorship in five countries: China, Iran, Oman, Qatar, and Kuwait. Finally, we conclude by discussing potential approaches to circumvent censorship on I2P.
-
an empirical study of the i2p Anonymity Network and its censorship resistance
Internet Measurement Conference, 2018Co-Authors: Nguyen Phong Hoang, Panagiotis Kintis, Manos Antonakakis, Michalis PolychronakisAbstract:Tor and I2P are well-known Anonymity Networks used by many individuals to protect their online privacy and Anonymity. Tor's centralized directory services facilitate the understanding of the Tor Network, as well as the measurement and visualization of its structure through the Tor Metrics project. In contrast, I2P does not rely on centralized directory servers, and thus obtaining a complete view of the Network is challenging. In this work, we conduct an empirical study of the I2P Network, in which we measure properties including population, churn rate, router type, and the geographic distribution of I2P peers. We find that there are currently around 32K active I2P peers in the Network on a daily basis. Of these peers, 14K are located behind NAT or firewalls. Using the collected Network data, we examine the blocking resistance of I2P against a censor that wants to prevent access to I2P using address-based blocking techniques. Despite the decentralized characteristics of I2P, we discover that a censor can block more than 95% of peer IP addresses known by a stable I2P client by operating only 10 routers in the Network. This amounts to severe Network impairment: a blocking rate of more than 70% is enough to cause significant latency in web browsing activities, while blocking more than 90% of peer IP addresses can make the Network unusable. Finally, we discuss the security consequences of the Network being blocked, and directions for potential approaches to make I2P more resistant to blocking.
Nguyen Phong Hoang - One of the best experts on this subject based on the ideXlab platform.
-
Measuring I2P Censorship at a Global Scale
arXiv: Computers and Society, 2019Co-Authors: Nguyen Phong Hoang, Sadie Doreen, Michalis PolychronakisAbstract:The prevalence of Internet censorship has prompted the creation of several measurement platforms for monitoring filtering activities. An important challenge faced by these platforms revolves around the trade-off between depth of measurement and breadth of coverage. In this paper, we present an opportunistic censorship measurement infrastructure built on top of a Network of distributed VPN servers run by volunteers, which we used to measure the extent to which the I2P Anonymity Network is blocked around the world. This infrastructure provides us with not only numerous and geographically diverse vantage points, but also the ability to conduct in-depth measurements across all levels of the Network stack. Using this infrastructure, we measured at a global scale the availability of four different I2P services: the official homepage, its mirror site, reseed servers, and active relays in the Network. Within a period of one month, we conducted a total of 54K measurements from 1.7K Network locations in 164 countries. With different techniques for detecting domain name blocking, Network packet injection, and block pages, we discovered I2P censorship in five countries: China, Iran, Oman, Qatar, and Kuwait. Finally, we conclude by discussing potential approaches to circumvent censorship on I2P.
-
an empirical study of the i2p Anonymity Network and its censorship resistance
Internet Measurement Conference, 2018Co-Authors: Nguyen Phong Hoang, Panagiotis Kintis, Manos Antonakakis, Michalis PolychronakisAbstract:Tor and I2P are well-known Anonymity Networks used by many individuals to protect their online privacy and Anonymity. Tor's centralized directory services facilitate the understanding of the Tor Network, as well as the measurement and visualization of its structure through the Tor Metrics project. In contrast, I2P does not rely on centralized directory servers, and thus obtaining a complete view of the Network is challenging. In this work, we conduct an empirical study of the I2P Network, in which we measure properties including population, churn rate, router type, and the geographic distribution of I2P peers. We find that there are currently around 32K active I2P peers in the Network on a daily basis. Of these peers, 14K are located behind NAT or firewalls. Using the collected Network data, we examine the blocking resistance of I2P against a censor that wants to prevent access to I2P using address-based blocking techniques. Despite the decentralized characteristics of I2P, we discover that a censor can block more than 95% of peer IP addresses known by a stable I2P client by operating only 10 routers in the Network. This amounts to severe Network impairment: a blocking rate of more than 70% is enough to cause significant latency in web browsing activities, while blocking more than 90% of peer IP addresses can make the Network unusable. Finally, we discuss the security consequences of the Network being blocked, and directions for potential approaches to make I2P more resistant to blocking.
Carmela Troncoso - One of the best experts on this subject based on the ideXlab platform.
-
Fingerprinting Tor’s Hidden Service Log Files Using a Timing Channel
2016Co-Authors: Juan A. Elices, Carmela TroncosoAbstract:Abstract—Hidden services are anonymously hosted services that can be accessed over Tor, an Anonymity Network. In this paper we present an attack that allows an entity to prove, once a machine suspect to host a hidden server has been confiscated, that such machine has in fact hosted a particular content. Our solution is based on leaving a timing channel fingerprint in the confiscated machine’s log file. In order to be able to fingerprint the log server through Tor we first study the noise sources: the delay introduced by Tor and the log entries due to other users. We then describe our fingerprint method, and analytically determine the detection probability and the rate of false positives. Finally, we empirically validate our results. I
-
fingerprinting tor s hidden service log files using a timing channel
International Workshop on Information Forensics and Security, 2011Co-Authors: Juan A. Elices, Fernando Perezgonzalez, Carmela TroncosoAbstract:Hidden services are anonymously hosted services that can be accessed over Tor, an Anonymity Network. In this paper we present an attack that allows an entity to prove, once a machine suspect to host a hidden server has been confiscated, that such machine has in fact hosted a particular content. Our solution is based on leaving a timing channel fingerprint in the confiscated machine's log file. In order to be able to fingerprint the log server through Tor we first study the noise sources: the delay introduced by Tor and the log entries due to other users. We then describe our fingerprint method, and analytically determine the detection probability and the rate of false positives. Finally, we empirically validate our results.
-
impact of Network topology on Anonymity and overhead in low latency Anonymity Networks
Privacy Enhancing Technologies, 2010Co-Authors: Claudia Diaz, Steven J. Murdoch, Carmela TroncosoAbstract:Low-latency anonymous communication Networks require padding to resist timing analysis attacks, and dependent link padding has been proven to prevent these attacks with minimal overhead. In this paper we consider low-latency Anonymity Networks that implement dependent link padding, and examine various Network topologies. We find that the choice of the topology has an important influence on the padding overhead and the level of Anonymity provided, and that Stratified Networks offer the best trade-off between them. We show that fully connected Network topologies (Free Routes) are impractical when dependent link padding is used, as they suffer from feedback effects that induce disproportionate amounts of padding; and that Cascade topologies have the lowest padding overhead at the cost of poor scalability with respect to Anonymity. Furthermore, we propose an variant of dependent link padding that considerably reduces the overhead at no loss in Anonymity with respect to external adversaries. Finally, we discuss how Tor, a deployed large-scale Anonymity Network, would need to be adapted to support dependent link padding.
Ivan Pustogarov - One of the best experts on this subject based on the ideXlab platform.
-
Deanonymization techniques for Tor and Bitcoin
Stanford Security Seminar, 2014Co-Authors: Ivan PustogarovAbstract:This thesis is devoted to low-resource off-path deanonymisation techniques for two popular systems, Tor and Bitcoin. Tor is a software and an Anonymity Network which in order to confuse an observer encrypts and re-routes traffic over random pathways through several relays before it reaches the destination. Bitcoin is a distributed payment system in which payers and payees can hide their identities behind pseudonyms (public keys) of their choice. The estimated number of daily Tor users is 2,000,000 which makes it arguable the most used Anonymity Network. Bitcoin is the most popular cryptocurrency with market capitalization about 3.5 billion USD. In the first part of the thesis we study the Tor Network. At the beginning we show how to remotely find out which Tor relays are connected. This effectively allows for an attacker to reduce Tor users’ Anonymity by ruling out impossible paths in the Network. Later we analyze the security of Tor Hidden Services. We look at them from different attack perspectives and provide a systematic picture of what information can be obtained with very inexpensive means. We expose flaws both in the design and implementation of Tor Hidden Services that allow an attacker to measure the popularity of arbitrary hidden services, efficiently collect hidden service descriptors (and thus get a global picture of all hidden services in Tor), take down hidden services and deanonymize hidden services. In the second part we study Bitcoin Anonymity. We describe a generic method to deanonymize a significant fraction of Bitcoin users and correlate their pseudonyms with their public IP addresses. We discover that using Bitcoin through Tor not only provides limited level of Anonymity but also exposes the user to man-in-the middle attacks in which an attacker controls which Bitcoin blocks and transactions the user is aware of. We show how to fingerprint Bitcoin users by setting an “address cookie” on their computers. This can be used to correlate the same user across different sessions, even if he uses Tor, hidden-services or multiple proxies. Finally, we describe a new anonymous decentralized micropayments scheme in which clients do not pay services with electronic cash directly but submit proof of work shares which the services can resubmit to a crypto-currency mining pool. Services credit users with tickets that can later be used to purchases enhanced services.
-
2013 IEEE Symposium on Security and Privacy Trawling for Tor Hidden Services: Detection, Measurement, Deanonymization
2013Co-Authors: Alex Biryukov, Ivan PustogarovAbstract:Abstract—Tor is the most popular volunteer-based Anonymity Network consisting of over 3000 volunteer-operated relays. Apart from making connections to servers hard to trace to their origin it can also provide receiver privacy for Internet services through a feature called “hidden services”. In this paper we expose flaws both in the design and implementation of Tor’s hidden services that allow an attacker to measure the popularity of arbitrary hidden services, take down hidden services and deanonymize hidden services. We give a practical evaluation of our techniques by studying: (1) a recent case of a botnet using Tor hidden services for command and control channels; (2) Silk Road, a hidden service used to sell drugs and other contraband; (3) the hidden service of the DuckDuckGo search engine. Keywords-Tor; Anonymity Network; privacy; hidden services I
-
TorScan: Tracing Long-lived Connections and Differential Scanning Attacks
2013Co-Authors: Alex Biryukov, Ivan PustogarovAbstract:Abstract. Tor is a widely used Anonymity Network providing low-latency communication capabilities. Around 400,000 users per day use Tor to route TCP traffic through a sequence of relays; three hops are selected from a pool of currently almost 3000 volunteer-operated Tor relays to comprise a route through the Network for a limited time. In comparison to single-hop proxies, forwarding TCP streams through multiple relays increases the Anonymity of the users significantly: each hop along the route only knows its successor and predecessor. The Anonymity provided by Tor heavily relies on the hardness of linking a user’s entry and exit nodes. If an attacker gains access to the topological information about the Tor Network instead of having to consider the Network as a fully connected graph, this Anonymity may be reduced. In fact, we have found ways to probe the connectivity of a Tor relay. We demonstrate how the resulting leakage of the Tor Network topology can be used and present attacks to trace back a user from an exit relay to a small set of potential entry nodes.
-
Trawling for Tor Hidden Services: Detection, Measurement, Deanonymization
2013 IEEE Symposium on Security and Privacy, 2013Co-Authors: Alex Biryukov, Ivan Pustogarov, Roberto WeinmannAbstract:Tor is the most popular volunteer-based Anonymity Network consisting of over 3000 volunteer-operated relays. Apart from making connections to servers hard to trace to their origin it can also provide receiver privacy for Internet services through a feature called “hidden services”. In this paper we expose flaws both in the design and implementation of Tor’s hidden services that allow an attacker to measure the popularity of arbitrary hidden services, take down hidden services and deanonymize hidden services. We give a practical evaluation of our techniques by studying: (1) a recent case of a botnet using Tor hidden services for command and control channels; (2) Silk Road, a hidden service used to sell drugs and other contraband; (3) the hidden service of the DuckDuckGo search engine.
Alex Biryukov - One of the best experts on this subject based on the ideXlab platform.
-
2013 IEEE Symposium on Security and Privacy Trawling for Tor Hidden Services: Detection, Measurement, Deanonymization
2013Co-Authors: Alex Biryukov, Ivan PustogarovAbstract:Abstract—Tor is the most popular volunteer-based Anonymity Network consisting of over 3000 volunteer-operated relays. Apart from making connections to servers hard to trace to their origin it can also provide receiver privacy for Internet services through a feature called “hidden services”. In this paper we expose flaws both in the design and implementation of Tor’s hidden services that allow an attacker to measure the popularity of arbitrary hidden services, take down hidden services and deanonymize hidden services. We give a practical evaluation of our techniques by studying: (1) a recent case of a botnet using Tor hidden services for command and control channels; (2) Silk Road, a hidden service used to sell drugs and other contraband; (3) the hidden service of the DuckDuckGo search engine. Keywords-Tor; Anonymity Network; privacy; hidden services I
-
TorScan: Tracing Long-lived Connections and Differential Scanning Attacks
2013Co-Authors: Alex Biryukov, Ivan PustogarovAbstract:Abstract. Tor is a widely used Anonymity Network providing low-latency communication capabilities. Around 400,000 users per day use Tor to route TCP traffic through a sequence of relays; three hops are selected from a pool of currently almost 3000 volunteer-operated Tor relays to comprise a route through the Network for a limited time. In comparison to single-hop proxies, forwarding TCP streams through multiple relays increases the Anonymity of the users significantly: each hop along the route only knows its successor and predecessor. The Anonymity provided by Tor heavily relies on the hardness of linking a user’s entry and exit nodes. If an attacker gains access to the topological information about the Tor Network instead of having to consider the Network as a fully connected graph, this Anonymity may be reduced. In fact, we have found ways to probe the connectivity of a Tor relay. We demonstrate how the resulting leakage of the Tor Network topology can be used and present attacks to trace back a user from an exit relay to a small set of potential entry nodes.
-
Trawling for Tor Hidden Services: Detection, Measurement, Deanonymization
2013 IEEE Symposium on Security and Privacy, 2013Co-Authors: Alex Biryukov, Ivan Pustogarov, Roberto WeinmannAbstract:Tor is the most popular volunteer-based Anonymity Network consisting of over 3000 volunteer-operated relays. Apart from making connections to servers hard to trace to their origin it can also provide receiver privacy for Internet services through a feature called “hidden services”. In this paper we expose flaws both in the design and implementation of Tor’s hidden services that allow an attacker to measure the popularity of arbitrary hidden services, take down hidden services and deanonymize hidden services. We give a practical evaluation of our techniques by studying: (1) a recent case of a botnet using Tor hidden services for command and control channels; (2) Silk Road, a hidden service used to sell drugs and other contraband; (3) the hidden service of the DuckDuckGo search engine.