Title
TorWard: Discovery of malicious traffic over Tor
Abstract
Tor is a popular low-latency anonymous communication system. However, it is currently abused in various ways. Tor exit routers are frequently troubled by administrative and legal complaints. To gain an insight into such abuse, we design and implement a novel system, TorWard, for the discovery and systematic study of malicious traffic over Tor. The system can avoid legal and administrative complaints and allows the investigation to be performed in a sensitive environment such as a university campus. An IDS (Intrusion Detection System) is used to discover and classify malicious traffic. We performed comprehensive analysis and extensive real-world experiments to validate the feasibility and effectiveness of TorWard. Our data shows that around 10% Tor traffic can trigger IDS alerts. Malicious traffic includes P2P traffic, malware traffic (e.g., botnet traffic), DoS (Denial-of-Service) attack traffic, spam, and others. Around 200 known malware have been identified. To the best of our knowledge, we are the first to perform malicious traffic categorization over Tor.
Year
DOI
Venue
2014
10.1109/INFOCOM.2014.6848074
INFOCOM
Keywords
DocType
ISSN
denial-of-service attack traffic,Tor exit routers,intrusion detection system,IDS,malicious traffic discovery,P2P traffic,Intrusion Detection System,computer network security,low-latency anonymous communication system,DoS,Malicious Traffic,IDS alerts,Tor,telecommunication traffic,malicious traffic categorization,peer-to-peer computing,telecommunication network routing,spam
Conference
0743-166X
Citations 
PageRank 
References 
3
0.40
0
Authors
5
Name
Order
Citations
PageRank
Zhen Ling120925.15
Junzhou Luo21257153.97
Kui Wu3305.06
Wei Yu41338118.61
Xinwen Fu5105486.64