Tor dark network node deployment method based on multi-objective optimization and randomized confusion

By using multi-objective optimization and randomized obfuscation methods to deploy trap nodes in the Tor network, the problem of node tracking and traceability in the Tor network is solved, the concealment and survival rate of nodes are improved, and the deployment cost is controlled.

CN120017334AActive Publication Date: 2025-05-16SICHUAN UNIV

Patent Information

Application Number
CN202510089359.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-16
Estimated Expiration
2045-01-21

AI Technical Summary

Technical Problem

In Tor anonymous network, the challenge of tracking the source dark web nodes is that Tor's multi-hop proxy mechanism brings difficulties to traffic correlation analysis, and deploying trap nodes requires increasing the probability of being selected, while weighing the deployment cost and concealment.

Method used

The Tor darknet node deployment method based on multi-objective optimization and randomized obfuscation is adopted. By collecting node consensus files and statistical data, local connection graphs are built, node centrality is calculated, trap node deployment scheme is optimized using NSGA-II algorithm, and node detection resistance is improved through randomized obfuscation.

Benefits of technology

Effective deployment of trap nodes improves the traceability and traceability capabilities in the Tor network, enhances the concealment and survival rate of nodes, and controls the deployment cost.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017334A_ABST
    Figure CN120017334A_ABST
Patent Text Reader

Abstract

The invention provides a Tor dark web node deployment method based on a multi-objective optimization algorithm and randomized confusion. The method specifically comprises the following steps: collecting a node consensus file and a server descriptor file in a Tor directory server, and collecting node statistical data in a Tor Metric website to be used in subsequent steps; establishing a plurality of circuit connections in the time period, querying node information and link information in the circuit by using a Tor control protocol, and constructing a local connection graph; calculating node centrality measurement scores and a time sequence average value of the node centrality measurement scores to serve as a monitoring view field of nodes in the graph; the monitoring view, the selected probability and the deployment cost of the nodes are selected as target functions needing to be optimized, a Pareto optimal solution is calculated through a multi-target optimization algorithm, and node information in the Pareto optimal solution is used as a local optimal deployment scheme; and performing feature confusion on the local optimal deployment scheme from two aspects of statistical information and behaviors of the nodes, and taking the feature confusion as a final trap node deployment scheme.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security, and in particular to a Tor darknet node deployment method based on multi-objective optimization and randomized obfuscation. Background Art

[0002] With the advancement of science and technology, computer networks are developing rapidly at an unprecedented momentum. While enjoying the convenience brought by the Internet of Everything, people are also facing the risk of personal privacy leakage. In order to achieve personal privacy protection and censorship avoidance, anonymous communication networks came into being. Low-latency anonymous communication systems represented by Tor, JAP, and I2P are widely used in various aspects of the Internet. Among them, Tor (The Second Generation Onion Router) is currently the most widely used anonymous network with the largest user base. It encrypts and protects the communication process based on a multi-hop proxy mechanism; uses directory authority to store global network status; uses the SOCKS protocol as an anonymous proxy for the application layer protocol; while providing client anonymity to protect user privacy, it also provides hidden services to ensure the anonymity of the recipient (i.e., the service provider). It can provide network services without leaking the server IP address.

[0003] While Tor brings low latency and versatility, its high concealment and strong anti-traceability characteristics are increasingly used to spread terrorist actions and politically sensitive information as a springboard for cyber attacks. Tracking and tracing nodes in anonymous networks is particularly important in dark web governance. If the entry and exit nodes of a Tor circuit can be successfully controlled, the sender can be deanonymized through data packet comparison to complete the tracking and tracing. However, Tor's multi-hop proxy mechanism poses challenges to traffic correlation analysis. In order to achieve tracking and tracing, implanting trap nodes in the Tor anonymous network is a feasible solution. Existing studies have made trap nodes the RP nodes and entry nodes in the circuit, and used intersection attacks to trace the IP addresses of hidden services. Therefore, deploying trap nodes is extremely important for tracking and tracing anonymous communications; and increasing the probability of trap nodes being selected, while balancing the deployment cost and trap node monitoring field of view, and ensuring the concealment and survival rate of trap nodes are also current research difficulties.

[0004] The present invention proposes a Tor dark network node deployment method based on multi-objective optimization and randomized obfuscation. Specifically, it includes: collecting node consensus files and server descriptor files in the Tor directory server, collecting node statistics in the Tor Metrics website, and forming a local knowledge base; establishing a number of Tor circuit connections within a time period, and using the Tor control protocol to query the node information and link information in the circuit, and constructing a Tor local connection graph; using multiple centrality measurement methods to calculate the node centrality score, and calculating its time series average value as the monitoring field of the node in the local connection graph of the dark network; selecting the monitoring field of the relay node, the probability of the relay node being selected, and the deployment cost as the objective function to be optimized, using the multi-objective optimization algorithm NSGA-II to calculate the Pareto optimal solution, and using the node information therein as the local optimal deployment plan; feature obfuscating the local optimal deployment plan from the two perspectives of the statistical information and behavior of the relay node as the final trap node deployment plan. Summary of the invention

[0005] In view of this, an embodiment of the present invention proposes a Tor darknet node deployment method based on multi-objective optimization and randomized obfuscation, which can effectively deploy trap nodes in the Tor network and collect traffic information, providing support for tracking and tracing of anonymous communications.

[0006] A Tor darknet node deployment method based on multi-objective optimization and randomized obfuscation, the method comprising:

[0007] Step 1: Use Tor control protocol to build Tor darknet local connection graph;

[0008] Step 2: Calculate the monitoring field of view of nodes in the local communication graph of the dark network;

[0009] Step 3: Obtain the Pareto optimal solution of the Tor network trap node deployment plan based on the multi-objective optimization algorithm as the basis for deploying trap nodes;

[0010] Step 4: Improve the anti-detection capability of the trap node based on randomized obfuscation;

[0011] Step 5: Use the obtained local optimal deployment plan to deploy trap nodes in the Tor darknet.

[0012] Preferably, in step 1, the process of constructing the local connection graph of the dark web includes:

[0013] Use a web crawler to periodically crawl consensus files and server descriptor files from the Tor authority directory management agency;

[0014] Use the list of available nodes in the consensus file as a graph Nodes in , use the node's server descriptor as the node's identifier; select The IP addresses of the most popular hidden services and common domains in the Alexa Top 100 ;use A local server as , set up its Tor client on all local servers;

[0015] Initialize the local connection graph of the dark network, where , , ;

[0016] Select time period , the time period Depend on time slices; using the Tor control protocol, send a control protocol signal to the Tor client, so that the local server and A Tor circuit is established between the two nodes; the Tor circuit is composed of a guard node, an intermediate node, and an exit node selected by a Tor client from a list of available nodes in a consensus file through an adjustable bandwidth weighted routing selection algorithm;

[0017] Repeat the above steps to continuously obtain new Tor circuit connections until the time period End; in time slice In the process, all established circuits are queried through the Tor control protocol to obtain the server descriptor of the relay node, and the descriptor is used to reversely query the IP address of the relay node from the consensus file; the time slice is represented by <relay node IP, relay node IP, time slice number> Zhongtong Link Map The network connectivity graph is obtained by taking the relay node IP address as the node and the relay node link connection relationship as the edge.

[0018] Preferably, in step 2, the monitoring field of view calculation process of the nodes in the Tor dark network local connection graph includes:

[0019] Local connectivity graph Each relay node in the network performs a centrality measurement calculation, wherein the centrality measurement methods include node degree centrality, Katz centrality, proximity centrality, harmony centrality measurement, and weighted PageRank algorithm;

[0020] The node degree centrality is calculated for each relay node, and the formula is as follows:

[0021] ;

[0022] in Representation Node Degree in the network, Indicates the size of the network, i.e. the number of nodes;

[0023] The Katz centrality is calculated for each relay node using the following formula:

[0024] ;

[0025] in is the adjacency matrix of the network, is the attenuation factor, which must be less than The reciprocal of the absolute value of the largest eigenvalue;

[0026] The closeness centrality of each relay node is calculated as follows:

[0027] ;

[0028] in, Representation Node and The distance between Indicates the size of the network, i.e. the number of nodes;

[0029] The harmony centrality is calculated for each relay node, and the formula is as follows:

[0030] ;

[0031] in Is a node and The distance between Indicates the size of the network, i.e. the number of nodes;

[0032] The weighted PageRank score of each relay node is calculated using the following formula:

[0033] ;

[0034] in, represents the size of the network, i.e. the number of nodes, is the damping factor in the PageRank score, Is a node To Node The weight of the edge, Is with the node A collection of connected nodes;

[0035] The multiple centrality scores are normalized as follows:

[0036] ;

[0037] in, represents a certain type of centrality score of the relay node, represents the set of centrality scores of relay nodes, represents the normalized centrality score;

[0038] And calculate the average of the centrality scores as the relay nodes The centrality measure score of ;

[0039] After a certain period of time, count the total number of nodes in the Tor local network connection graph at this time , and each time slice Nodes in The centrality score of , the temporal centrality score of a node is calculated using the following formula:

[0040] ;

[0041] The node The temporal centrality score represents the monitoring view of the node in the local connection graph of the Tor dark web.

[0042] Preferably, in step 3, the method for determining a Tor trap node deployment scheme based on multi-objective optimization includes:

[0043] Perform a random walk on the local dark network connection graph described in step 2 to generate There are node selection schemes, each of which contains nodes; calculate the monitoring field of view of each node in each solution and obtain the bandwidth value of the node from the consensus file;

[0044] The monitoring field of view of the relay node, the probability of the relay node being selected, and the deployment cost are used as the objective functions to be optimized, which are expressed as follows: :

[0045] ;

[0046] ;

[0047] ;

[0048] The optimization goal is to minimize the three objective function values, so each objective function is negative; among them, Representative The negative of the sum of the temporal centrality scores of the deployment schemes, which is used to represent the overall Tor network monitoring vision of the deployment scheme;

[0049] Representative The trap node deployment scheme is the negative of the sum of the probabilities of a node being selected as a relay node for circuit construction under the adjustable bandwidth routing selection algorithm;

[0050] Representative deployment The negative of the total cost of the trap node deployment scheme, where A parameter representing the direct proportion of cost to bandwidth capacity;

[0051] Using the NSGA-II algorithm, based on the Pareto dominance principle, for each node deployment plan , for the three objective functions, compare them with other solutions respectively. If all objective functions are satisfied Are less than or equal to , and on at least one objective function, Strictly less than ,Right now:

[0052] ;

[0053] ;

[0054] Solution Dominate , and recorded as ; If the trap node deployment scheme For all other deployment scenarios All satisfied ,but is a Pareto optimal solution, save the solution to the Pareto optimal solution set, and continue to perform the above operation on the remaining deployment solutions until there is no Pareto optimal solution in the initial trap node deployment solution set;

[0055] Merge the Pareto optimal solution set and remove duplicate relay nodes. and The nodes in the , local optimal trap node deployment scheme is obtained.

[0056] Preferably, in step 4, the Tor trap node anti-detection method based on randomized obfuscation includes:

[0057] Use a web crawler to collect various statistics and performance data about the Tor network from the Tor Metrics website;

[0058] The IP locations of the relay nodes in the local dark network connection map described in step 2 are counted to obtain the top 15 countries or regions in terms of the number of locations; for each node in the trap node deployment solution, a random selection is made from the country or region as the IP location of the node, and a suitable VPS is selected from multiple cloud service providers;

[0059] Use the data on Tor Metrics to count the distribution of relay node nicknames, ports, and client versions in a given time period, and select the corresponding parameters with the highest proportion as the configuration of the trap node;

[0060] The running time of the trap node is randomized and confused. Before deploying the trap node, the average running time of the relay nodes newly added to the Tor network in the past 7 hours is counted and recorded as , represents the floating running time of the relay nodes newly added to the Tor network; the average running time of the relay nodes newly added to the Tor network in the past 7 days is counted and recorded as , represents the stable operation time of the newly added relay node in the Tor network, and calculates ;

[0061] Calculate the number of trap nodes that are operating normally per hour (i.e. ) is the probability mass function of the Poisson distribution ,in The value range of is the number of nodes N in the trap node deployment scheme set in step 3, as shown in the following formula:

[0062] ;

[0063] The calculated Poisson distribution includes the number of trap nodes that are operating normally per hour. The corresponding probability value ,According to the probability distribution, the number of trap nodes that are operating normally within the current hour is set by random selection.

[0064] Preferably, in step 5, based on the local optimal deployment scheme, the method for deploying trap nodes in the Tor darknet includes:

[0065] Use the local optimal trap node deployment plan described in step 3 to determine the bandwidth capacity and export traffic strategy of the trap node; use the randomized obfuscation method described in step 4 to confuse the external features of the relay node and determine the IP location, nickname, Tor port, and Tor client version of the trap node; use the Poisson distribution described in step 4 to dynamically adjust the number of normally operating trap nodes every hour after deploying the trap node in the Tor dark web. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings required for describing the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the embodiments of the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0067] Figure 1 A flow chart of a Tor darknet node deployment method based on multi-objective optimization and randomized obfuscation according to an embodiment of the present invention;

[0068] Figure 2 is the Poisson distribution parameter in the embodiment of the present invention Schematic diagram of the probability mass function curve when . DETAILED DESCRIPTION

[0069] The specific implementation of the present invention is further described in detail below in conjunction with the drawings and specific implementation methods. The following examples or drawings are used for the present invention, but are not used to limit the scope of the present invention.

[0070] See also Figure 1 , Figure 1 A flowchart of a Tor darknet node deployment method based on multi-objective optimization and randomized obfuscation provided in an embodiment of the present application includes:

[0071] Step 1: Use Tor control protocol to build Tor darknet local connection graph;

[0072] Step 2: Calculate the temporal centrality scores of nodes in the Tor darknet local connection graph;

[0073] Step 3: Obtain the Pareto optimal solution of the Tor network trap node deployment plan based on multiple objectives as the basis for deploying trap nodes;

[0074] Step 4: Improve the anti-detection capability of the trap node based on randomized obfuscation;

[0075] Step 5: Use the local optimal deployment solution to deploy trap nodes in the Tor darknet.

[0076] The specific steps for constructing a local connection graph of the dark web include:

[0077] Step 1a: In an embodiment of the present invention, a directory server with the most running relay nodes is selected from the eight directory servers (Directory Authorities Server) of the Tor authoritative directory management agency, and the consensus file (Consensus Document) and server descriptor file (ServerDescriptor) therein are obtained regularly with a time slice of 1 hour.

[0078] Step 1b: Use the list of available nodes from the consensus file As a node in the graph, use the node's relay node server descriptor as the node's identifier; select several popular hidden services and the IP addresses of common table websites in Alexa Top100 ; Use several local servers , and set up Tor clients in the servers; initialize the connection graph ,in ;

[0079] Optionally, in order to reduce the scale of calculation, some nodes in the list of available nodes can be selected as nodes in the graph; for example, 30% of the available nodes are randomly selected to constitute the nodes in the local dark network connection graph.

[0080] Step 1c: Select a time period , and divide it into continuous time slices, i.e. Based on the Tor Control Protocol, a control protocol signal is sent to Tor itself, which makes the local server and A Tor circuit is established between the two. The Tor client selects the route from Randomly select 3 relay nodes to build a Tor circuit;

[0081] For example, the time period T is set to 96 hours and divided into 96 consecutive time slices, each time slice is 1 hour;

[0082] Preferably, the Python Stem library is used as the control library for interacting with the Tor client. Stem can obtain detailed information about each node in the Tor network through Tor control protocol signals, including the node's IP address, port, bandwidth, role (such as exit node or entry node), and other information.

[0083] Step 1d: Repeat step 1c to continuously obtain new Tor circuit connections; in the time slice In the Tor client, each time a new Tor circuit is created, the Tor client maintains three alternative circuit information; the Python Stem library is used to query the server descriptor of the relay node in each circuit, and the detailed information of the relay node is reversed from the server descriptor file published by the Tor Project based on the server descriptor, including the node's IP address, bandwidth capacity, Tor client version, open port information, node nickname, and description fingerprint and other basic information; the time slice is generated using the method of <relay node IP, relay node IP, time slice serial number> Tor local network connection diagram The network connectivity graph is obtained by taking the relay node IP address as the node and the relay node link connection relationship as the edge;

[0084] For example, in the time slice In the process, the user receives a link message back. , then the edge set Add Edges and , and the edge between the local server node and the guard node , the edge between the exit node and the remote server ; Repeat the above operation in each time slice until the time Finally, a local connected graph G of the dark network is constructed. At this time, the number of nodes and edges in graph G is the largest.

[0085] The specific steps for calculating the monitoring field of view of nodes in the local connection graph of the dark network are as follows:

[0086] Step 2a: Calculate the temporal centrality measurement score for each relay node in the local connectivity graph G, wherein the centrality measurement methods include node degree centrality, Katz centrality, proximity centrality, and harmony centrality measurement methods.

[0087] Step 2b: Calculate the node degree centrality for each relay node , the formula is as follows:

[0088] ;

[0089] in Representation Node Degree in the network, Indicates the size of the network, that is, the number of nodes.

[0090] Step 2c: Calculate Katz centrality for each relay node , the formula is as follows:

[0091] ;

[0092] in is the adjacency matrix of the network, is the attenuation factor, which must be less than The reciprocal of the absolute value of the largest eigenvalue.

[0093] Step 2d: Calculate proximity centrality for each relay node , the formula is as follows:

[0094] ;

[0095] in, Representation Node and The distance between Indicates the size of the network, that is, the number of nodes.

[0096] Step 2e: Calculate the harmony centrality for each relay node, the formula is as follows:

[0097] ;

[0098] in Is a node and The distance between Indicates the size of the network, that is, the number of nodes.

[0099] Step 2f: Calculate the weighted PageRank score of each relay node using the following formula:

[0100] ;

[0101] in, represents the size of the network, i.e. the number of nodes, is the damping factor in the PageRank score, Is a node To Node The weight of the edge, Is with the node A collection of connected nodes.

[0102] Step 2g: First, perform minimum-maximum normalization on multiple centrality scores. The normalization processing formula is as follows:

[0103] ;

[0104] in, Represents a certain type of centrality score of a relay node, Represents the set of centrality scores of all relay nodes;

[0105] And calculate the average of the centrality scores as the relay nodes The centrality score of .

[0106] Step 2h: Calculate the temporal centrality scores of nodes in the Tor darknet local connection graph; After the end, count the total number of nodes in the local connection graph at this time , and each time slice Nodes in The centrality score of , the temporal centrality score of a node is calculated using the following formula:

[0107] ;

[0108] Optionally, you can Choose Time Slice to , calculate the nodes in this time period The temporal centrality score of is:

[0109] ;

[0110] Use the calculated temporal centrality scores as nodes monitoring field of view.

[0111] The specific steps of the Tor trap node deployment scheme determination method based on multi-objective optimization are as follows:

[0112] Step 3a: Initialize the individual, select nodes from the local connection graph of the dark network described in step 1d using the random walk algorithm, generate M node selection schemes, each of which contains N nodes; for each scheme, calculate the centrality scores of each node, and query the node bandwidth capacity from the consensus file;

[0113] For example, the number of node selection schemes M is set to 15; the number of nodes in each scheme is set to 30% of the total number of nodes in the Tor darknet local connection graph G, and a random walk is performed starting from the node with the largest in- and out-degree in G. An out-edge is randomly selected to reach the next node. If the current node has no out-degree, a random jump is performed. Each time a new node is visited, its result is added to the set S until the walk is terminated when the Nth node is visited.

[0114] Step 3b: Select the three indicators of Tor network local monitoring field of view, relay node selection probability, and deployment cost as the objective function to be optimized. Here, the objective function is converted into a three-dimensional vector ;in:

[0115] ;

[0116] ;

[0117] ;

[0118] Select minimization as the optimization goal, and take negative values ​​for the three objective functions; among them, Representative The negative of the sum of the temporal centrality scores of the trap node deployment schemes is used to represent the overall Tor network monitoring vision of the deployment scheme;

[0119] Representative The negative of the sum of the probabilities of the trap node deployment scheme being selected as a relay node for circuit construction under the adjustable bandwidth routing selection algorithm (the algorithm uses the node bandwidth information provided in the Tor consensus file for calculation), where different calculation methods are used depending on the type of node (guard, intermediate, exit); Indicates the current deployment plan The bandwidth of each node, Indicates the total bandwidth of nodes with Exit flag. Represents the total bandwidth of nodes with the Guard flag. Represents the total bandwidth of nodes with Guard and Exit flags. Represents the total bandwidth of nodes without Guard and Exit flags. Respectively represent the weight of the entry protection node and the weight of the exit protection node;

[0120] Representative deployment The negative of the total cost of the trap node deployment scheme, where A parameter representing the direct proportion of cost to bandwidth capacity;

[0121] Preferably, the proportional parameter is obtained by statistically analyzing the bandwidth capacity and price of existing cloud servers. .

[0122] Step 3c: Use the NSGA-II algorithm to deploy a solution for each node according to the Pareto dominance principle. , for the three elements in the objective function , respectively compare the node deployment scheme with other schemes, if it satisfies all objective functions Are less than or equal to , and on at least one objective function, Strictly less than ,Right now:

[0123] ; ;

[0124] Solution Dominate , and recorded as , if the trap node deployment scheme For all other deployment scenarios All satisfied ,but If it is a Pareto optimal solution, save it to the Pareto optimal trap node deployment solution set, and continue to perform the above operation on the remaining deployment solutions until there is no Pareto optimal solution in the initial trap node deployment solution set;

[0125] Merge the Pareto optimal trap node deployment plan set to remove duplicate relay nodes, and The nodes in the , local optimal trap node deployment scheme is obtained.

[0126] The specific steps of the Tor trap node anti-detection method based on randomized obfuscation are as follows:

[0127] Step 4a: Select a time period and use a web crawler to collect information such as node nicknames, open ports, and client versions of active nodes in the Tor network from the Tor Metrics website; obtain corresponding information based on the fields in the running relay node information in the available node list in the consensus file;

[0128] For example, the corresponding information of each field is as follows:

[0129] v corresponds to the Tor client version running on the relay node;

[0130] pr corresponds to the supported protocol type and version; w corresponds to the bandwidth capacity of the relay node;

[0131] p corresponds to the egress traffic policy of the relay node, indicating which ports’ traffic is accepted;

[0132] r corresponds to the basic information of the relay node, including the nickname of the relay node, identity fingerprint, description fingerprint, descriptor release time, routing port of the relay node, and directory port;

[0133] a corresponds to the IPv6 address and port of the relay node;

[0134] s corresponds to the status flag of the relay node.

[0135] Step 4b: Count the IP locations of the relay nodes in the Tor local connection graph described in step 1d to obtain the top 15 countries or regions in terms of the number of locations; randomly select an IP location as a trap node from these countries or regions, and select a suitable VPS (virtual private servers) from multiple cloud service provider platforms.

[0136] Step 4c: Based on the data on Tor Metric, count the distribution percentages of relay node nicknames, ports, and Tor client versions in the recent period (e.g., the past week), and count the corresponding parameters with the highest percentage as the configuration of the trap node, and confuse the trap node in terms of features.

[0137] Step 4d: Randomize and confuse the running time of the trap node. Before deploying the trap node, count the average running time of the relay nodes newly added to the Tor network in the past 7 hours, and record it as , represents the floating running time of the relay nodes newly added to the Tor network; the average running time of the relay nodes newly added to the Tor network in the past 7 days is counted and recorded as , represents the stable operation time of the newly added relay node in the Tor network, and calculates .

[0138] Step 4e: Calculate the number of trap nodes that are operating normally in each hour (i.e. ) is the probability mass function of the Poisson distribution ,in The value range of is the number of nodes N in the trap node deployment scheme set in step 3a, as shown in the following formula:

[0139] ;

[0140] The calculated Poisson distribution includes the number of trap nodes that are operating normally per hour. The corresponding probability value ,According to the probability distribution, the number of trap nodes that are operating normally within the current hour is set by random selection;

[0141] like Figure 2 As shown, the parameters in step 4d are It will be dynamically adjusted according to the activity of Tor network nodes: when short-term activity is high, The value of will become smaller, at this time the overall function curve of the probability mass function will be steeper, and the number of trap nodes operating normally per hour will change more dramatically; when the short-term activity is low, The value of will become larger, and the overall function curve of the probability mass function will be relatively flat, and the number of trap nodes operating normally per hour will change relatively smoothly; in this way, the behavioral characteristics of the trap nodes are hidden among the normal nodes of the Tor network.

[0142] The specific steps for deploying trap nodes in the Tor network are as follows:

[0143] Step 5a: Use the optimized deployment plan of the local dark web connection map described in step 3c to determine the bandwidth capacity and export traffic strategy of the trap node; use the randomized obfuscation method described in steps 4b and 4c to determine the IP location, nickname, Tor port, and Tor client version of the trap node.

[0144] Step 5b: When the trap nodes are deployed, the Poisson distribution parameters are calculated according to the method described in step 4d. , calculate the Poisson distribution of the number of trap nodes operating normally per hour according to step 4e, and set the number of trap nodes operating normally in the current hour according to the probability distribution; repeat steps 4d and 4e every hour to recalculate and , and randomly select according to the obtained probability distribution, set the number of trap nodes that operate normally in the current hour, and dynamically start or stop the Tor client on the trap node according to the number of trap nodes that operate normally in the previous hour.

[0145] Finally, it should be noted that the above is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, it is still possible for those skilled in the art to modify the technical solutions described in the aforementioned embodiments or to make equivalent replacements for some of the technologies therein.

[0146] Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A Tor darknet node deployment method based on multi-objective optimization and randomized obfuscation, characterized in that: The method comprises: Step 1. Construct a Tor darknet local connection graph based on the Tor control protocol; Step 2. Calculate the monitoring field of view of nodes in the Tor darknet local connection graph; Step 3. Obtain the Pareto optimal solution of the trap node deployment plan based on the multi-objective optimization algorithm as the basis for deploying the trap nodes; Step 4. Improve the anti-detection capability of the trap node based on randomized obfuscation; Step 5. Use the obtained local optimal deployment plan to deploy trap nodes in the Tor darknet.

2. According to claim 1, a Tor darknet node deployment method based on multi-objective optimization and randomized obfuscation is characterized in that: The step 1 comprises: Use a web crawler to periodically crawl consensus files and server descriptor files from the Tor authority directory management agency; Use the list of available nodes in the consensus file as a graph Nodes in , use the node's server descriptor as the node's identifier; select The IP addresses of the most popular hidden services and common domains in the Alexa Top 100 ;use A local server as , set up its Tor client on all local servers; Initialize the local connection graph of the dark network, where , , ; Select time period , the time period Depend on time slices; using the Tor control protocol, send a control protocol signal to the Tor client, so that the local server and A Tor circuit is established between the two nodes; the Tor circuit is composed of a guard node, an intermediate node, and an exit node selected by a Tor client from a list of available nodes in a consensus file through an adjustable bandwidth weighted routing selection algorithm; Repeat the above steps to continuously obtain new Tor circuit connections until the time period End; in time slice In the process, all established circuits are queried through the Tor control protocol to obtain the server descriptor of the relay node, and the descriptor is used to reversely query the IP address of the relay node from the consensus file; the time slice is represented by <relay node IP, relay node IP, time slice number> Zhongtong Link Map The network connectivity graph is obtained by taking the relay node IP address as the node and the relay node link connection relationship as the edge.

3. According to claim 2, a Tor darknet node deployment method based on multi-objective optimization and randomized obfuscation is characterized in that: The step 2 comprises: Local connectivity graph Each relay node in the network performs a centrality measurement calculation, wherein the centrality measurement methods include node degree centrality, Katz centrality, proximity centrality, harmony centrality measurement, and weighted PageRank algorithm; The node degree centrality is calculated for each relay node, and the formula is as follows: ; in Representation Node Degree in the network, Indicates the size of the network, i.e. the number of nodes; The Katz centrality is calculated for each relay node using the following formula: ; in is the adjacency matrix of the network, is the attenuation factor, which must be less than The reciprocal of the absolute value of the largest eigenvalue; The closeness centrality of each relay node is calculated as follows: ; in, Representation Node and The distance between Indicates the size of the network, i.e. the number of nodes; The harmony centrality is calculated for each relay node, and the formula is as follows: ; in Is a node and The distance between Indicates the size of the network, i.e. the number of nodes; The weighted PageRank score of each relay node is calculated using the following formula: ; in, represents the size of the network, i.e. the number of nodes, is the damping factor in the PageRank score, Is a node To Node The edge weights of Is with the node A collection of connected nodes; The multiple centrality scores are normalized as follows: ; in, represents a certain type of centrality score of the relay node, represents the set of centrality scores of relay nodes, Represents the normalized centrality score; and calculates the average centrality score as the relay node The centrality measure score of ; After a certain period of time, count the total number of nodes in the Tor local network connection graph at this time , and each time slice Nodes in The centrality score of , the temporal centrality score of a node is calculated using the following formula: ; The node The temporal centrality score represents the monitoring field of the node in the local connection graph of the Tor dark web.

4. According to claim 3, a Tor darknet node deployment method based on multi-objective optimization and randomized obfuscation is characterized in that: As a basis for deploying the trap node, the step 3 includes: Perform a random walk on the local dark network connection graph described in step 2 to generate There are node selection schemes, each of which contains nodes; calculate the monitoring field of view of each node in each solution and obtain the bandwidth value of the node from the consensus file; The monitoring field of view of the relay node, the probability of the relay node being selected, and the deployment cost are used as the objective functions to be optimized, which are expressed as follows: : ; ; ; The optimization goal is to minimize the three objective function values, so each objective function is negative; among them, Representative The negative of the sum of the temporal centrality scores of the deployment schemes, which is used to represent the overall Tor network monitoring vision of the deployment scheme; Representative The trap node deployment scheme is the negative of the sum of the probabilities of a node being selected as a relay node for circuit construction under the adjustable bandwidth routing selection algorithm; Representative deployment The negative of the total cost of the trap node deployment scheme, where A parameter representing the direct proportion of cost to bandwidth capacity; Using the NSGA-II algorithm, based on the Pareto dominance principle, for each node deployment plan , for the three objective functions, compare them with other solutions respectively. If all objective functions are satisfied Are less than or equal to , and on at least one objective function, Strictly less than ,Right now: ; ; Solution Dominate , and recorded as ; If the trap node deployment scheme For all other deployment scenarios All satisfied ,but is a Pareto optimal solution, save the solution to the Pareto optimal solution set, and continue to perform the above operation on the remaining deployment solutions until there is no Pareto optimal solution in the initial trap node deployment solution set; merge the Pareto optimal solution set, remove duplicate relay nodes, and The nodes in the , local optimal trap node deployment scheme is obtained.

5. According to claim 4, a Tor darknet node deployment method based on multi-objective optimization and randomized obfuscation is characterized in that: The step 4 comprises: Use a web crawler to collect various statistics and performance data about the Tor network from the Tor Metrics website; The IP locations of the relay nodes in the local dark network connection map described in step 2 are counted to obtain the top 15 countries or regions in terms of the number of locations; for each node in the trap node deployment solution, a random selection is made from the country or region as the IP location of the node, and a suitable VPS is selected from multiple cloud service providers; Use the data on Tor Metrics to count the distribution of relay node nicknames, ports, and client versions in a given time period, and select the corresponding parameters with the highest proportion as the configuration of the trap node; The running time of the trap node is randomized and confused. Before deploying the trap node, the average running time of the relay nodes newly added to the Tor network in the past 7 hours is counted and recorded as , represents the floating running time of the relay nodes newly added to the Tor network; the average running time of the relay nodes newly added to the Tor network in the past 7 days is counted and recorded as , represents the stable operation time of the newly added relay node in the Tor network, and calculates ; Calculate the number of trap nodes that are operating normally per hour (i.e. ) is the probability mass function of the Poisson distribution ,in The value range of is the number of nodes N in the trap node deployment scheme set in step 3, as shown in the following formula: ; The calculated Poisson distribution includes the number of trap nodes that are operating normally per hour. The corresponding probability value ,According to the probability distribution, the number of trap nodes that are operating normally within the current hour is set by random selection.

6. A Tor darknet node deployment method based on multi-objective optimization and randomized obfuscation according to claim 5, characterized in that: Deploy a trap node in the Tor darknet, step 5 includes: Use the local optimal trap node deployment plan described in step 3 to determine the bandwidth capacity and export traffic strategy of the trap node; use the randomized obfuscation method described in step 4 to confuse the external features of the relay node and determine the IP location, nickname, Tor port, and Tor client version of the trap node; use the Poisson distribution described in step 4 to dynamically adjust the number of normally operating trap nodes every hour after deploying the trap node in the Tor dark web.

Citation Information

Patent Citations

  • Hidden service Guard node identification method based on active circuit abnormity

    CN115412340A

  • Method for constructing Tor network anonymous link in combination with node reputation

    CN115766566A

  • Malicious node monitoring-oriented network flow monitoring point overall selection method and device

    CN117411690A

Cited By

  • Multi-granularity anonymous user flow identification method and device and medium

    CN120785603A