Hidden Service Guard Node Identification Method Based on Active Circuit Abnormality

By actively constructing exceptions and log comparison analysis methods, identifying the Guard nodes of Tor hidden service, solving the problem of Guard node identification and improving the difficulty of attack defense.

CN115412340BActive Publication Date: 2025-06-13SOUTHEAST UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211037164.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-26
Publication Date
2025-06-13
Estimated Expiration
2042-08-26

AI Technical Summary

Technical Problem

The Guard node identification of Tor hidden service is difficult to implement, making it easier to carry out deanonymization attacks on hidden services.

Method used

By actively constructing exceptions that can be identified by nodes, filtering Middle nodes, and identifying the hidden service Guard nodes through comparison and analysis of log information. Specific steps include specially made RPO packet generation, Middle node filtering based on active circuit exceptions, and hidden service Guard node identification.

Benefits of technology

It effectively avoids abnormal detection of hidden services, increases the success rate of circuit establishment, and improves the recognition efficiency of Guard nodes through active circuit abnormal identification features.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115412340B_ABST
    Figure CN115412340B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for identifying Guard nodes of hidden services based on active circuit anomalies. The method specifically includes: (1) constructing a special RPO packet to associate the hidden service with the corresponding communication circuit, avoiding a large amount of local storage overhead and being able to avoid anomaly detection that the hidden service may perform. (2) Actively constructing circuit anomalies at the RPO to force the hidden service to continuously establish new circuits for communication, so as to increase the probability of the special Middle node being selected. (3) Identifying the Guard nodes of the hidden service through comparative analysis of node log information and obtaining specific information about the Guard nodes. This method can identify the Guard nodes used by the hidden services deployed in the Tor dark web, which is conducive to further analysis and supervision of the hidden services.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of anonymity networks, and particularly relates to a method for identifying Guard nodes of hidden services based on active circuit anomalies. Background Art

[0002] In order to protect the privacy of users, the Tor anonymous communication system ensures high anonymity through the onion routing method. Therefore, it is urgent to supervise Tor hidden services. Through research, it is found that Guard nodes are relay nodes that directly communicate with hidden services and have a direct impact on the effect of de-anonymizing hidden services. Once the specific information of Guard nodes is known, attacks such as traffic analysis for de-anonymizing hidden services will become easier. In addition, Guard nodes can also expose the relationships between hidden services. For example, when multiple hidden services are bound to the same Tor process, these hidden services will select the same Guard node, thus exposing their subordinate relationships. Due to security and other considerations, the Guard nodes of hidden services will not change for a long period of time. Therefore, identifying Guard nodes has high practical value. Summary of the Invention

[0003] Object of the Invention: There are a large number of hidden services in the Tor dark web, and supervision needs to be strengthened urgently. The present invention proposes a method for identifying Guard nodes of hidden services based on active circuit anomalies. This method actively constructs recognizable anomalies for nodes, continuously screens Middle nodes, and then identifies the Guard nodes of hidden services through comparative analysis of log information.

[0004] Technical Solution: The present invention proposes a method for identifying Guard nodes of hidden services based on active circuit anomalies. The solution is divided into three parts, namely, special RPO generation, Middle node screening based on active circuit anomalies, and identification of Guard nodes of hidden services, which are specifically as follows:

[0005] (1) RPO data packet generation algorithm: Generate RPO data packets at the client, and the content thereof has a corresponding relationship with the hidden service domain name to ensure that the relevant domain name can be corresponded to at the RPO;

[0006] (2) Middle node screening based on active circuit anomalies: By actively constructing circuit anomalies corresponding to the RPO, force the HS to continuously reselect circuits and replace the Middle nodes in the circuits until the deployed Middle nodes are selected;

[0007] (3) Hidden service Guard node identification: By identifying actively constructed circuit anomalies at the deployed Middle nodes, and then through comparative analysis of the Middle node logs and RPO node logs, the Guard nodes corresponding to the hidden services are determined.

[0008] Furthermore, the RPO data packet generation algorithm described in step (1) specifically includes:

[0009] (11) Associating the Rend-cookie with the hidden service domain name: During the RPO communication process, the Rend-cookie remains unchanged all the time. Therefore, this variable is used to store the hidden service domain name information.

[0010] (12) Hidden service anomaly detection avoidance: Since the size of the Rend-cookie is 20 bytes and its normal generation is random, some hidden services deployed on the Tor dark web will detect these generated Rend-cookie values and actively disconnect the possibly actively constructed and abnormal RPO connections. Therefore, by specifying the values of 4 of its bytes and randomly generating the remaining 16 bytes, the randomness of the Rend-cookie is ensured, the anomaly detection of the hidden service is avoided, and at the same time, the collision probability of the Rend-cookie can be almost ignored.

[0011] Furthermore, the screening of Middle nodes based on actively constructed circuit anomalies described in step (2) specifically includes:

[0012] (21) Deploy multiple nodes and wait to be selected as Middle nodes by the HS to expose their Guard node information.

[0013] (22) By configuring the torrc file, bandwidth, and operating status of the deployed nodes, the probability of their being selected as Middle nodes is increased.

[0014] (23) The RPO node parses all Rend-cookie values. If it finds that a Rend-cookie is actively constructed, it records this timestamp and the previous-hop IP address, adds an active delay, and disconnects the HS-RPO circuit.

[0015] Furthermore, the identification of hidden service Guard nodes described in step (3) specifically includes:

[0016] (31) The Middle node listens to and records each circuit anomaly situation, records the command packet circuits with specific sequential characteristics, and records the time of each received command packet.

[0017] (32) The Middle node log and the RPO node log are compared and analyzed to identify the constructed active circuit anomaly. The characteristics of the active circuit anomaly include: (1) the next hop IP address of the Middle node is the same as the previous hop IP address of the RPO node; (2) the timestamp distribution of the RPO receiving data packet and the Middle node receiving data packet is offset;

[0018] (33) Based on the identification results of the comparative analysis, for the discovered active circuit anomaly, the Guard node of the hidden service is identified according to the hidden service domain name information contained in its Rend-cookie and the previous hop Guard node information recorded in the Middle node log.

[0019] Beneficial effects: Compared with the prior art, the present invention has the following significant advantages:

[0020] 1. Using a specially crafted RPO packet, the Rend-cookie field in the packet carries the information of the corresponding hidden service, thus avoiding the overhead of maintaining the relationship between the hidden service and the circuit. In addition, the semi-random generation method of Rend-cookie can effectively avoid abnormal detection of hidden services and increase the success rate of circuit establishment.

[0021] 2. By modifying the configuration files and properties of the deployed nodes and reducing the probability of selecting other types of nodes, the probability of being selected as a Middle node is increased. At the same time, the active circuit abnormality method is used to continuously switch the circuit, which improves the efficiency of Middle node selection.

[0022] 3. By actively constructing circuit anomalies at the RPO, the HS is forced to continuously change the circuit, thereby increasing the efficiency of the deployed nodes being selected. At the same time, the features of the active circuit anomaly construction can be used to identify the anomaly, and then the hidden service is associated with the circuit to identify the Guard node. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 It is a flow chart of establishing the HS-RPO circuit of the present invention.

[0024] Figure 2 It is a diagram of the Guard node discovery solution of the present invention. DETAILED DESCRIPTION

[0025] The present invention designs and implements a hidden service Guard node identification scheme based on active circuit anomalies to discover Guard nodes used by hidden services in the dark web. The main processes are generation of special RPO packets, screening of Middle nodes based on active circuit anomalies, and identification of hidden service Guard nodes, which specifically include:

[0026] 1. Specialized RPO Data Packet Generation

[0027] During the process of the client establishing communication with the hidden service, the client needs to transmit the selected RPO to the hidden service through IPO. Subsequently, the hidden service will actively connect to this RPO to establish the final communication circuit with the client. During this process, when the client selects the RPO, a 20 - byte random value, namely Rend - cookie, will be generated in the data packet and retained throughout the communication process.

[0028] In the present invention, by artificially modifying the value of Rend - cookie in the client, the domain name information of the hidden service is encoded therein, so as to always retain the correspondence between the hidden service and the circuit during the communication process without additional overhead. Additionally, since the Rend - cookie value generated by a normal client is completely random, therefore, when only some of its bytes are modified, it can be ensured that the modification will not be detected by the hidden service, thus avoiding the abnormal detection of the hidden service.

[0029] Since the size of Rend - cookie is 20 bytes and each byte ranges from 0 to 255, there are 256 20 different values. If 4 bytes in Rend - cookie are artificially specified and the remaining 16 bytes are randomly generated, theoretically 256 4 customized values can be generated, and the collision probability of each value is only Therefore, its collision probability is extremely low and can be ignored.

[0030] 2. Middle Node Screening Based on Active Circuit Abnormality

[0031] In order to successfully identify the Guard node, the present invention needs to deploy specialized relay nodes and make them the Middle nodes for the communication of the hidden service. Therefore, the present invention needs to maximize the probability that the deployed nodes are selected as Middle nodes by the hidden service.

[0032] In the Consensus file of the Tor system, the bandwidth of each Tor relay node is published in the form of "Bandwidth=xxx". At the same time, the flag bits set by the authoritative directory server for each Tor relay node are also displayed in the Consensus file, such as the Guard flag bit (indicating that it can be selected as an entry node), the Exit flag bit (indicating that it can be selected as an exit node), the HSDir flag bit (indicating that it can become a hidden service directory server), etc. When the Tor program selects a Middle node, it will first calculate the weight value of each node being selected based on information such as the bandwidth value of each node and its corresponding flag bits, and then make a random selection according to the weight value. Generally speaking, the weight value calculation formula for each node is as shown below.

[0033] final_weight = weight * this_bw

[0034] Among them, final_weight represents the calculated final weight value, weight is the weight value calculated according to the node flag bits, etc., and this_bw represents the node bandwidth size. When selecting a Middle node, its weight value depends on whether its relay node flag bit is Guard-only, Exit-only, Guard&Exit or None. The corresponding values are w mg 、w me 、w mm 、w md . Among them, None means that the Tor relay node has neither a Guard flag bit nor an Exit flag bit.

[0035] w mg 、w me 、w mm 、w md The values of are calculated from the Consensus file. Generally speaking, w mg < w mm And the values of w me and w md are 0. Therefore, if you want to increase the probability of a node being selected as a Middle node, try not to let the node obtain a Guard or Exit flag bit. Among them, the Exit flag bit needs to configure the torrc file to obtain, while the Guard flag bit requires the node to have a relatively high bandwidth and run continuously and stably for a certain period of time.

[0036] When this special Rend - cookie value is received at the RPO, a circuit anomaly can be actively constructed to disconnect the link between the hidden service and the RPO. At this time, the Middle node will receive a specific Destroy command packet, and due to the circuit disconnection, it will force the HS to actively re - establish the circuit and continuously re - select three - hop nodes to link to the RPO. By this method, the probability that the nodes deployed in the present invention are selected as the Middle nodes of the hidden service can be increased. Once a deployed node is selected, the node can obtain the address information of its previous hop, i.e., the Guard node. Since the Guard node of the hidden service, once selected, generally remains for 2 - 3 months, it gives the attacker sufficient time to implement the above - mentioned probability - based attack.

[0037] 3. Hidden service Guard node identification

[0038] After the circuit is actively disconnected, the HS will actively re - select the circuit and has a certain probability of selecting the Middle node we deployed. At this time, the Middle node will receive circuit packets in a fixed order. Since the circuit will be disconnected at the RPO in the experiment, theoretically, a certain delay time can be actively set. In this paper, certain filtering conditions are added and recorded at the Middle node, and finally, the hidden service Guard node is determined by comparing and analyzing the logs recorded by the Middle node and the logs recorded by the RPO node.

[0039] As Figure 1 shown, when the HS - RPO circuit is constructed, the Middle node will receive 1 CELL_CREATE2 packet and 2 CELL_RELAY_EARLY packets. In addition, the HS will send 1 CELL_RELAY_EARLY packet with a relay command of RELAY_COMMAND_RENDEZVOUS1 after the circuit is constructed. Subsequently, the RPO will construct an active circuit anomaly to disconnect the circuit. Therefore, at the Middle node, it should receive 1 CELL_CREATE2 packet (command value is 10), 3 CELL_RELAY_EARLY packets (command value is 9), and 1 CELL_DESTROY packet (command value is 4). Therefore, in the Middle node, only the Tor Cell packet circuit with the order feature of 10 -> 9 -> 9 -> 9 -> 4 needs to be recorded, and the timestamp of each received Tor Cell packet should be recorded.

[0040] The method for comparing and analyzing the logs of the Middle node and the RPO node is as follows:

[0041] (1) The next - hop IP address at the Middle is the same as the previous - hop IP address at the RPO;

[0042] (2) Since the circuit will be broken at the RPO during the experiment and a certain time delay can be actively set, it is assumed in this paper that the timestamp of the packet received at the RPO is t1, the timestamp of receiving the 3rd CELL_EARLY_RELAY packet at the Middle is t2, and the timestamp of receiving the CELL_DESTROY packet is t3. Normally, the values of t3 - t2 and t1 - t2 should satisfy a certain distribution. However, if data packets are sent after a certain active delay, it will cause a certain shift in the time distribution of t3 - t2. We use this anomaly as a filtering condition and conduct a comparative analysis to associate the hidden service with the corresponding circuit and identify the Guard node.

[0043] Figure 2 Shows the overall solution for Guard node identification in this experiment.

[0044] The English abbreviations used in this invention and their Chinese explanations are as follows:

[0045] 1. Tor, whose full name is The Onion Router, and its Chinese explanation is onion routing;

[0046] 2. IP, whose full name is Internet Protocol, and its Chinese explanation is Internet Protocol;

[0047] 3. RPO, whose full name is RendezvousPoint, and its Chinese explanation is rendezvous node;

[0048] 4. IPO, whose full name is IntroductionPoint, and its Chinese explanation is introduction node;

[0049] 5. HS, whose full name is Hidden Server, and its Chinese explanation is hidden server;

[0050] 6. HSDir, whose full name is Hidden Service Directory, and its Chinese explanation is hidden service directory server.

[0051] Finally, it should be noted that: The above embodiments are only used to illustrate the technical solutions of this application rather than to limit its protection scope. Although this application has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: After reading this application, those skilled in the art can still make various changes, modifications, or equivalent replacements to the specific implementation manners of the application. However, these changes, modifications, or equivalent replacements are all within the protection scope of the pending claims of the application.

Claims

1. A method for identifying hidden service Guard nodes based on active circuit anomalies, characterized in that, the method comprises the following steps: (1) RPO packet generation algorithm: Generate RPO packets at the client, the content of which has a corresponding relationship with the hidden service domain name to ensure that the relevant domain name can be corresponded to at the RPO; The RPO packet generation algorithm specifically includes: (11) Associate the Rend-cookie with the hidden service domain name: During the RPO communication process, the Rend-cookie remains unchanged all the time, so this variable is used to store the hidden service domain name information; (12) Avoidance of hidden service anomaly detection: Since the size of the Rend-cookie is 20 bytes and its normal generation is random, some hidden services deployed on the Tor dark web will detect these generated Rend-cookie values and actively disconnect the possibly actively constructed and abnormal RPO connections; Therefore, by specifying the values of 4 of its bytes and randomly generating the remaining 16 bytes; (2) Middle node screening based on active circuit anomalies: By actively constructing circuit anomalies corresponding to the RPO, force the HS to continuously re-select the circuit and replace the Middle nodes in the circuit until the deployed Middle nodes are selected; The Middle node screening based on active circuit anomalies specifically includes: (21) Deploy multiple nodes and wait to be selected as Middle nodes by the HS to expose their Guard node information; (22) Improve the probability of being selected as a Middle node by configuring the torrc file, bandwidth and operating status of the deployed nodes; (23) The RPO node parses all Rend-cookie values. If it finds that the Rend-cookie is actively constructed, record this timestamp and the previous-hop IP address, add an active delay and disconnect the HS-RPO circuit; (3) Hidden service Guard node identification: Identify the actively constructed circuit anomalies at the deployed Middle nodes, and then determine the Guard nodes corresponding to the hidden services through comparative analysis of the Middle node logs and the RPO node logs; The hidden service Guard node identification specifically includes: (31) The Middle node listens to and records each circuit anomaly situation, records the command packet circuits with specific sequential characteristics, and records the time of each received command packet; (32) Compare and analyze the Middle node logs and the RPO node logs to identify the actively constructed circuit anomalies. The characteristics of the actively constructed circuit anomalies include: (1) The next-hop IP address of the Middle node is the same as the previous-hop IP address of the RPO node; (2) There is an offset in the timestamp distribution of the RPO receiving the data packet and the Middle node receiving the data packet; (33)Based on the recognition results of the comparative analysis, for the discovered active circuit anomalies, according to the hidden service domain name information contained in their Rend-cookies and the information of the previous-hop Guard node recorded in the Middle node logs, identify the Guard nodes of the hidden service.