How Unique is Your .onion? An Analysis of the Fingerprintability of Tor Onion Services
Rebekah Overdorf, Marc Juarez, Gunes Acar, Rachel Greenstadt, Claudia, Diaz

TL;DR
This study analyzes the fingerprintability of Tor onion services, revealing high variability in vulnerability and identifying features that influence detectability, which informs better defenses against fingerprinting attacks.
Contribution
It provides the largest multi-level feature analysis of onion site fingerprintability, highlighting site-specific vulnerabilities and informing countermeasure design.
Findings
High variability in site classification accuracy
Features related to traffic and webpage design influence fingerprintability
Misclassification analysis suggests redesign strategies for less vulnerability
Abstract
Recent studies have shown that Tor onion (hidden) service websites are particularly vulnerable to website fingerprinting attacks due to their limited number and sensitive nature. In this work we present a multi-level feature analysis of onion site fingerprintability, considering three state-of-the-art website fingerprinting methods and 482 Tor onion services, making this the largest analysis of this kind completed on onion services to date. Prior studies typically report average performance results for a given website fingerprinting method or countermeasure. We investigate which sites are more or less vulnerable to fingerprinting and which features make them so. We find that there is a high variability in the rate at which sites are classified (and misclassified) by these attacks, implying that average performance figures may not be informative of the risks that website fingerprinting…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Hate Speech and Cyberbullying Detection · Spam and Phishing Detection
