Playing Server Hide and Seek on the Tor Anonymity Network
Paul Syverson
Naval Research Laboratory
Monday, April 24, 2:00PM
Burchard 124
Computer Science Department
Stevens Institute of Technology
Abstract
Hidden services have many uses from resisting server DDoS to anonymous blogging. Undergroundmedia.org has published a guide to "Torcasting" (anonymity-preserving and censorship-resistant podcasting). And both the Electronic Frontier Foundation and Reporters Without Borders have issued guides that describe using hidden services via Tor to protect the safety of dissidents as well as resist censorship.
Our primary focus in this presentation will be attacks. I will start by describing the basic motivation and design of the Tor network and of hidden services. I will then demonstrate attacks we have recently carried out in experiments on the deployed Tor network that uncover the location of hidden servers in a matter of minutes. I will also tell you how to protect against these attacks. I will present entry guard nodes and other countermeasures to these attacks that have recently been implemented and describe how they counter the attacks.
Work on attacks and countermeasures is joint with Lasse Øverlier and
will be published at the IEEE Symposium on Security and Privacy. The
paper "Locating Hidden Servers" can be obtained at http://www.onion-router.net.