首页> 外文会议>IFIP Networking Conference >Onion Pass: Token-Based Denial-of-Service Protection for Tor Onion Services
【24h】

Onion Pass: Token-Based Denial-of-Service Protection for Tor Onion Services

机译:洋葱通行证:基于令牌的拒绝服务的托盘服务

获取原文

摘要

The Tor network is widely recognized as an important tool to preserve online privacy. In addition to anonymous Internet access, it allows hosting anonymous services, i.e., Onion Services. However, connecting to an Onion Service is realized in a way that makes them vulnerable to Denial-of-Service attacks (DoS). In this work, we propose Onion Pass, an extension of the Tor protocol that utilizes anonymous cryptographic tokens to mitigate the issue. Clients can solve a challenge to acquire tokens that later can be presented to the Onion Service. The Onion Service can thus differentiate between valid and malicious requests when under attack. Please note that Onion pass is agnostic on the specific challenge-response scheme and follows a design philosophy that puts Onion Services in control of the Onion Pass protocol. We implemented a prototype of Onion Pass and present experimental results that indicate its potential to prevent DoS attacks on Onion Services by reducing their CPU usage required to identify malicious requests by a factor of 47.
机译:TOR网络被广泛认可为保护在线隐私的重要工具。除了匿名互联网接入外,它还允许托管匿名服务,即洋葱服务。然而,连接到洋葱服务以使其容易受到拒绝服务攻击(DOS)的方式实现。在这项工作中,我们提出了洋葱通行证,是使用匿名加密令牌来减轻问题的Tor协议的延伸。客户可以解决挑战以获得令牌可以呈现给洋葱服务。因此,洋葱服务可以在攻击时区分有效和恶意的请求。请注意,洋葱通行证是关于特定挑战 - 响应计划的不可知论由,遵循一个设计哲学,将洋葱服务控制洋葱通行定议。我们实施了洋葱通行证的原型,并提出了实验结果,表明它通过减少识别恶意请求所需的CPU使用率来防止DOS攻击对洋葱服务的潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号