One Bad Apple Spoils the Bunch: Exploiting P2P Applications to Trace and Profile Tor Users

نویسندگان

  • Stevens Le Blond
  • Pere Manils
  • Chaabane Abdelberi
  • Mohamed Ali Kâafar
  • Claude Castelluccia
  • Arnaud Legout
  • Walid Dabbous
چکیده

Tor is a popular low-latency anonymity network. However, Tor does not protect against the exploitation of an insecure application to reveal the IP address of, or trace, a TCP stream. In addition, because of the linkability of Tor streams sent together over a single circuit, tracing one stream sent over a circuit traces them all. Surprisingly, it is unknown whether this linkability allows in practice to trace a significant number of streams originating from secure (i.e., proxied) applications. In this paper, we show that linkability allows us to trace 193% of additional streams, including 27% of HTTP streams possibly originating from “secure” browsers. In particular, we traced 9% of all Tor streams carried by our instrumented exit nodes. Using BitTorrent as the insecure application, we design two attacks tracing BitTorrent users on Tor. We run these attacks in the wild for 23 days and reveal 10,000 IP addresses of Tor users. Using these IP addresses, we then profile not only the BitTorrent downloads but also the websites visited per country of origin of Tor users. We show that BitTorrent users on Tor are over-represented in some countries as compared to BitTorrent users outside of Tor. By analyzing the type of content downloaded, we then explain the observed behaviors by the higher concentration of pornographic content downloaded at the scale of a country. Finally, we present results suggesting the existence of an underground BitTorrent ecosystem on Tor.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

P2P Network Trust Management Survey

Peer-to-peer applications (P2P) are no longer limited to home users, and start being accepted in academic and corporate environments. While file sharing and instant messaging applications are the most traditional examples, they are no longer the only ones benefiting from the potential advantages of P2P networks. For example, network file storage, data transmission, distributed computing, and co...

متن کامل

Compromising Tor Anonymity Exploiting P2P Information Leakage

Privacy of users in P2P networks goes far beyond their current usage and is a fundamental requirement to the adoption of P2P protocols for legal usage. In a climate of cold war between these users and anti-piracy groups, more and more users are moving to anonymizing networks in an attempt to hide their identity. However, when not designed to protect users information, a P2P protocol would leak ...

متن کامل

Eclipse and Re-Emergence of Anonymous P2P Storage Network Overlay Services

As soon as anonymous peer-to-peer (P2P) storage networks came to be in the early 2000s [8, 9, 11, 14], developers found themselves with a new playground for creating privacy enhancing tools. In many ways different to the now dominant client-server architecture, a whole generation of distributed overlay services emerged, offering a viable option for asynchronous messaging and bulletin boards. To...

متن کامل

De-anonymizing BitTorrent Users on Tor

Privacy of users in Peer-to-peer (P2P) networks goes far beyond their current usage and is a fundamental requirement to the adoption of P2P protocols for legal usage. In a climate of cold war between P2P filesharing users and anti-piracy groups, more and more users are moving to anonymizing networks in an attempt to hide their identity. However, when not designed to protect users information, a...

متن کامل

Regulating Behavior in Online Communities

According to an old English saying, “one bad apple spoils the whole barrel.” In online communities there’s some truth to this notion. A stalker, thief, troll, or impersonator can ruin the community experience for the majority of members who respect the intent of the site and the feelings of others. Misbehavior need not be illegal to be destructive. People who consume benefits without giving any...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • CoRR

دوره abs/1103.1518  شماره 

صفحات  -

تاریخ انتشار 2011