An Extensive Evaluation of the Internet's Open Proxies
Akshaya Mani, Tavish Vaidya, David Dworken, Micah Sherr

TL;DR
This comprehensive study of over 107,000 open proxies over 50 days reveals high unresponsiveness, widespread malicious behavior including cryptojacking and malware injection, and compares their reliability unfavorably to Tor exit relays.
Contribution
The paper provides the first large-scale, detailed analysis of open proxies' availability, behavior, and malicious activities, highlighting their risks and contrasting them with Tor.
Findings
Over 92% of listed open proxies are unresponsive.
Numerous proxies manipulate content for cryptojacking and malware.
Tor relays show no malicious behavior, indicating higher reliability.
Abstract
Open proxies forward traffic on behalf of any Internet user. Listed on open proxy aggregator sites, they are often used to bypass geographic region restrictions or circumvent censorship. Open proxies sometimes also provide a weak form of anonymity by concealing the requestor's IP address. To better understand their behavior and performance, we conducted a comprehensive study of open proxies, encompassing more than 107,000 listed open proxies and 13M proxy requests over a 50 day period. While previous studies have focused on malicious open proxies' manipulation of HTML content to insert/modify ads, we provide a more broad study that examines the availability, success rates, diversity, and also (mis)behavior of proxies. Our results show that listed open proxies suffer poor availability--more than 92% of open proxies that appear on aggregator sites are unresponsive to proxy requests.…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Advanced Malware Detection Techniques · Network Security and Intrusion Detection
