RAPTOR: Routing Attacks on Privacy in Tor
Yixin Sun, Anne Edmundson, Laurent Vanbever, Oscar Li, Jennifer, Rexford, Mung Chiang, Prateek Mittal

TL;DR
This paper introduces Raptor, a suite of new routing attacks on Tor that exploit Internet routing asymmetries, churn, and manipulation to compromise user anonymity, supported by real-world data analysis and attack demonstrations.
Contribution
It presents novel routing attack techniques on Tor using BGP hijacks, interceptions, and routing churn, along with monitoring frameworks to detect such attacks.
Findings
Raptor attacks can significantly increase user deanonymization risk.
Historical BGP and Traceroute data confirm attack feasibility.
Real-world attacks demonstrate practical vulnerabilities.
Abstract
The Tor network is a widely used system for anonymous communication. However, Tor is known to be vulnerable to attackers who can observe traffic at both ends of the communication path. In this paper, we show that prior attacks are just the tip of the iceberg. We present a suite of new attacks, called Raptor, that can be launched by Autonomous Systems (ASes) to compromise user anonymity. First, AS-level adversaries can exploit the asymmetric nature of Internet routing to increase the chance of observing at least one direction of user traffic at both ends of the communication. Second, AS-level adversaries can exploit natural churn in Internet routing to lie on the BGP paths for more users over time. Third, strategic adversaries can manipulate Internet routing via BGP hijacks (to discover the users using specific Tor guard nodes) and interceptions (to perform traffic analysis). We…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Network Security and Intrusion Detection · Cryptography and Data Security
