• DocumentCode
    3604350
  • Title

    TorWard: Discovery, Blocking, and Traceback of Malicious Traffic Over Tor

  • Author

    Zhen Ling ; Junzhou Luo ; Kui Wu ; Wei Yu ; Xinwen Fu

  • Author_Institution
    Sch. of Comput. Sci. & Eng., Southeast Univ., Nanjing, China
  • Volume
    10
  • Issue
    12
  • fYear
    2015
  • Firstpage
    2515
  • Lastpage
    2530
  • Abstract
    Tor is a popular low-latency anonymous communication system. It is, however, currently abused in various ways. Tor exit routers are frequently troubled by administrative and legal complaints. To gain an insight into such abuse, we designed and implemented a novel system, TorWard, for the discovery and the systematic study of malicious traffic over Tor. The system can avoid legal and administrative complaints, and allows the investigation to be performed in a sensitive environment such as a university campus. An intrusion detection system (IDS) is used to discover and classify malicious traffic. We performed comprehensive analysis and extensive real-world experiments to validate the feasibility and the effectiveness of TorWard. Our results show that around 10% Tor traffic can trigger IDS alerts. Malicious traffic includes P2P traffic, malware traffic (e.g., botnet traffic), denial-of-service attack traffic, spam, and others. Around 200 known malwares have been identified. To mitigate the abuse of Tor, we implemented a defense system, which processes IDS alerts, tears down, and blocks suspect connections. To facilitate forensic traceback of malicious traffic, we implemented a dual-tone multi-frequency signaling-based approach to correlate botnet traffic at Tor entry routers and that at exit routers. We carried out theoretical analysis and extensive real-world experiments to validate the feasibility and the effectiveness of TorWard for discovery, blocking, and traceback of malicious traffic.
  • Keywords
    computer network security; digital forensics; invasive software; law; peer-to-peer computing; telecommunication network routing; telecommunication traffic; IDS alerts; P2P traffic; Tor exit routers; TorWard; administrative complaints; botnet traffic; denial-of-service attack traffic; dual-tone multifrequency signaling-based approach; forensic traceback; intrusion detection system; legal complaints; low-latency anonymous communication system; malicious traffic traceback; malware traffic; spam; suspect connections; university campus; Bandwidth; Law; Logic gates; Malware; Protocols; Servers; Intrusion Detection System; Malicious Traffic; Tor; intrusion detection system; malicious traffic;
  • fLanguage
    English
  • Journal_Title
    Information Forensics and Security, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1556-6013
  • Type

    jour

  • DOI
    10.1109/TIFS.2015.2465934
  • Filename
    7182328