Source-linked AI summary

Content and popularity analysis of Tor hidden services

Alex Biryukov, Ivan Pustogarov, Fabrice Thill, Ralf-Philipp Weinmann

arXiv:1308.6768v2cs.CR

TL;DR

Tor hidden services support both protected speech and illicit activity, but their decentralized and incomplete address landscape has limited comprehensive measurement. This paper exploits Tor flaws to collect and analyze hidden-service descriptors, including ports, HTTP(S) content, popularity, client deanonymization, and tracking. It finds varied content, roughly balanced legal and illegal service counts, and popularity concentrated among botnet command centers and adult-content resources.

  • Problem

    The paper asks which types of services predominate among Tor hidden services despite incomplete public address lists and decentralized storage.

  • Method

    The authors exploit Tor protocol and implementation flaws to mine descriptors, scan ports, classify HTTP(S) content, estimate popularity, and analyze client deanonymization and service tracking.

  • Results

    The content of hidden services is varied, legal and illegal services are nearly equal in number, and the most popular services include botnet command centers and adult-content resources.

  • Takeaways & Limitations

    Popularity is more concentrated in botnet-related and adult-content services than the overall content distribution, while hidden-service uses span both legal and illegal activities.

Abstract

from arXiv · show

Tor hidden services allow running Internet services while protecting the location of the servers. Their main purpose is to enable freedom of speech even in situations in which powerful adversaries try to suppress it. However, providing location privacy and client anonymity also makes Tor hidden services an attractive platform for every kind of imaginable shady service. The ease with which Tor hidden services can be set up has spurred a huge growth of anonymously provided Internet services of both types. In this paper we analyse the landscape of Tor hidden services. We have studied Tor hidden services after collecting 39824 hidden service descriptors on 4th of Feb 2013 by exploiting protocol and implementation flaws in Tor: we scanned them for open ports; in the case of HTTP services, we analysed and classified their content. We also estimated the popularity of hidden services by looking at the request rate for hidden service descriptors by clients. We found that while the content of Tor hidden services is rather varied, the most popular hidden services are related to botnets.

I. INTRODUCTION

Tor hidden services support both protected expression and illicit activity, but the overall balance is difficult to measure because onion-address directories are incomplete and decentralized. The paper addresses this gap by collecting a broad service set and analyzing its ports, popularity, and content.

  • The landscape includes services for freedom of speech, contraband exchange, botnet command centers, and ordinary uses such as web publishing or messaging.
  • Published onion-address lists are incomplete, while hidden services are decentralized and rarely link to one another, preventing exhaustive traditional crawling.
  • The study collected 39,824 unique onion addresses using a Tor flaw, then scanned ports, estimated popularity, and classified service content.

II. BACKGROUND

Tor hidden services are built into Tor’s anonymity architecture, which routes communication through relays while allowing services to conceal their locations. The paper introduces this architecture before discussing the flaws used in its measurements.

  • Tor provides anonymous client-to-server communication by proxying traffic through a chain of three relays.

A. Tor hidden services

Tor hidden services conceal server locations by routing client-server communication through rendezvous points and distributing service descriptors across changing directories. A shadowing flaw enabled the authors to collect onion addresses at scale.

  • Hidden services conceal their servers’ IP addresses by connecting anonymous client and service circuits through a rendezvous point.
  • A hidden service’s onion address is derived from the base-32 encoding of the first 10 bytes of its key’s SHA-1 digest, followed by “.onion”.
  • Operators publish descriptors containing public keys and introduction points to six directories, whose assignments change every 24 hours.
  • The shadowing flaw allowed the researchers to bypass the two-relays-per-IP limitation and gather onion addresses using 58 IP addresses.
  • By running multiple relays per IP and cycling active relays offline, an attacker can gradually make shadow relays responsible directories during a 24-hour period.
  • The study estimated hidden-service popularity by measuring clients’ request rates for service descriptors.

B. Guard nodes

Tor entry guards reduce the probability of traffic-confirmation attacks by limiting the relays a client uses as its entry points over a temporary period.

  • A Tor client initially selects three Guard-flagged relays and replaces its guard set only when fewer than two selected guards remain reachable.
  • Each guard set persists for a random duration of 30 to 60 days before expiration and replacement.

III. PORT SCANNING HIDDEN SERVICES

The study scanned collected onion addresses for open ports and found a broad service distribution, with port 55080 dominating and HTTP(S) and SSH also common. Certificate analysis additionally identified services whose public DNS names could enable deanonymization.

  • The scan covered 39,824 collected addresses, but descriptors were available for 24,511 and coverage reached 87% of all ports.A total of 22,007 ports were found open on the addresses with available descriptors.
  • The anomalous port-55080 responses were associated with Skynet-infected computers because the malware closes connections unless they are configured as forwarding traffic.
  • Port 55080 was open on more than 50% of onion addresses, while HTTP and HTTPS accounted for 22% and SSH for 5%.The scan found 495 unique port numbers overall.
  • Thirty-four hidden services used certificates whose common names corresponded to public DNS names, allowing service deanonymization.Additionally, 1,225 certificates were self-signed with mismatched common names, including 1,168 using the same TorHost name.

IV. CONTENT ANALYSIS

The content analysis classified HTTP(S) hidden services by language and topic after filtering the crawl, finding mostly English content and a substantial concentration in drugs, adult content, counterfeit goods, and weapons. The remaining services covered political, anonymity, service, and other categories.

  • The crawl connected to 6,579 of 7,114 open HTTP(S) ports, then retained 3,050 destinations after excluding sparse, duplicated, and error-page content.The initial crawl targeted 8,153 onion address–port pairs and excluded about half as inappropriate for classification.
  • English accounted for 84% of hidden-service content, with the remainder spanning 16 additional languages.Each non-English language constituted less than 3%.
  • Among 1,813 classified English-language onion addresses, drugs, adult content, counterfeit goods, and weapons comprised 44%.The classified set excluded 805 TorHost default pages from 2,618 English-language services.
  • Politics and Anonymity were among the most popular remaining categories, representing 9% and 8%, respectively.Politics included reporting and discussion of corruption, repression, human-rights violations, and freedom of speech; Anonymity included technical and political discussions and anonymous services.
  • The Services category included money laundering, escrow, and offers to hire killers or thieves, while some Silk Road–prefixed addresses included phishing sites.

V. POPULARITY MEASUREMENT

Popularity was estimated from client requests for hidden-service descriptors, but most requests concerned nonexistent descriptors and only a small fraction of published descriptors were requested. Among observed popular services, probable botnet infrastructure led the rankings, followed by Skynet bitcoin-pooling servers.

  • Of 1,031,176 requests for 29,123 descriptor IDs, researchers resolved 6,113 IDs to 3,140 onion addresses.Descriptor IDs were matched to derived daily IDs to account for changing identifiers and possible client time errors.
  • Directory logs indicated that 80% of client requests targeted nonexistent descriptors and only 10% of published descriptors were ever requested.This behavior persisted over several months, but the authors lacked a definitive explanation.
  • Probable botnet services were the most popular observed hidden services, while Skynet bitcoin-pooling servers ranked second with a request rate four times lower.The top services exposed port 80, returned 503 errors, and showed server-status pages with roughly 10 requests per second and about 330 KBytes/sec of traffic.
  • Silk Road ranked 18th with 1,175 requests per 2 hours, Freedom Hosting 27th with 694, and DuckDuckGo 157th with 55.Black Market Reloaded ranked 62nd with 172 requests; public mining pools Slush and Eligius received two and zero requests, respectively.

VI. TRACKING CLIENTS

The paper shows that a responsible hidden-service directory can embed a traffic signature in descriptor responses, enabling opportunistic client deanonymisation and geographic mapping.

  • VI. TRACKING CLIENTS: A compromised responsible HSDir can send a distinctive descriptor-response signature that reveals a client’s IP address when observed by an attacker-controlled Guard.The attack depends on the client’s Guard belonging to the attacker’s controlled set.
  • VI. TRACKING CLIENTS: Client activity patterns can distinguish Silk Road buyers from sellers, making seller identification particularly damaging to the marketplace’s reputation.The paper characterizes buyers as occasional visitors and sellers as periodic visitors.
  • VI. TRACKING CLIENTS: The method also supports collecting client IP addresses and producing a geographic map for users of a popular Goldnet hidden service.The paper presents this application in Figure 3.

VII. TRACKING DETECTION

The paper proposes detecting hidden-service tracking by identifying statistically non-random HSDir behavior, including unusual selection frequency, fingerprint changes, and proximity to descriptor IDs.

  • VII. TRACKING DETECTION: The detection method flags relays with unusually frequent selection, suspicious timing or fingerprint changes, and unusually close fingerprint-to-descriptor distances.Selection frequency is modeled with a binomial distribution, while fingerprint changes and proximity provide additional behavioral signals.
  • VII. TRACKING DETECTION: The first analysis year showed no clear tracking indication, while the second year’s fingerprint changes were attributed to the authors’ own servers.These observations provide controls against interpreting every anomalous relay behavior as external tracking.
  • VII. TRACKING DETECTION: Tracking analysis found clear evidence of at least two cases involving Silk Road in the third year, including relays taking over responsible HSDir positions.One case involved one of six HSDirs; another involved all six for a period before the takedown.
  • VII. TRACKING DETECTION: The authors conclude that combining fingerprint changes with descriptor-ID distance is the most reliable way to detect tracking.The method applies to hidden services beyond the Silk Road example.

VIII. CONCLUSIONS

The paper analyzes Tor hidden services to compare their content and popularity, finding a mixed service landscape but a concentration of popular services among botnet command centers and adult-content resources.

  • VIII. CONCLUSIONS: Hidden-service content includes both illegal or controversial services and resources devoted to human rights, freedom of speech, anonymity, and security.The paper reports that these two broad groups are present in nearly equal numbers.
  • VIII. CONCLUSIONS: The study mines hidden-service descriptors, scans open ports, classifies HTTP(S) content, and estimates service popularity.It addresses the difficulty of obtaining comprehensive hidden-service statistics by exploiting protocol and implementation flaws.
  • VIII. CONCLUSIONS: The most popular hidden services are botnet command-and-control centers and adult-content resources, with Silk Road among the 20 most popular.Popularity therefore differs from the broader diversity of observed content.
  • VIII. CONCLUSIONS: The paper also proposes opportunistic client deanonymisation and consensus-history analysis for detecting hidden-service tracking.The tracking analysis found three clear Silk Road cases, including one caused by the authors’ experiments.
Loading 1308.6768v2…