TORCHLIGHT: Shedding LIGHT on Real-World Attacks on Cloudless IoT Devices Concealed within the Tor Network
Yumingzhi Pan, Zhen Ling, Yue Zhang, Hongze Wang, Guangchi Liu,, Junzhou Luo, Xinwen Fu

TL;DR
This paper introduces TORCHLIGHT, a tool that detects threats on cloudless IoT devices by analyzing Tor network traffic, revealing widespread exploitation of vulnerabilities with significant real-world impact.
Contribution
We developed TORCHLIGHT to identify both known and unknown threats targeting cloudless IoT devices through innovative traffic analysis and large language model-based threat detection.
Findings
Attackers use Tor to conceal their identities when targeting IoT devices.
TORCHLIGHT analyzed 26 TB of traffic over 12 months, finding 45 vulnerabilities including 29 zero-days.
Approximately 12.71 million devices across 148 countries are affected.
Abstract
The rapidly expanding Internet of Things (IoT) landscape is shifting toward cloudless architectures, removing reliance on centralized cloud services but exposing devices directly to the internet and increasing their vulnerability to cyberattacks. Our research revealed an unexpected pattern of substantial Tor network traffic targeting cloudless IoT devices. suggesting that attackers are using Tor to anonymously exploit undisclosed vulnerabilities (possibly obtained from underground markets). To delve deeper into this phenomenon, we developed TORCHLIGHT, a tool designed to detect both known and unknown threats targeting cloudless IoT devices by analyzing Tor traffic. TORCHLIGHT filters traffic via specific IP patterns, strategically deploys virtual private server (VPS) nodes for cost-effective detection, and uses a chain-of-thought (CoT) process with large language models (LLMs) for…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsImpact of Light on Environment and Health
