The darknet is a hidden part of the internet that facilitates both legal and illegal activities. Anonymity networks like Tor enable users to access the darknet while maintaining privacy, making detection challenging. Existing Tor detection methods primarily rely on flow-based or statistical features, which require multiple packets for feature extraction. However, Tor traffic closely resembles standard TLS traffic, making traditional approaches less effective. Its unique encryption mechanisms introduce distinctive data characteristics, particularly in entropy. This study presents a novel entropy-based approach to distinguishing Tor from nonTor traffic by leveraging byte-level entropy metrics, specifically Entropy_1_Hex and Entropy_2_Hex, along with their normalized versions (Norm_Entropy_1_Hex and Norm_Entropy_2_Hex), A recurrent neural network (RNN), known for its effectiveness in processing sequential data, is employed for classification. Experimental results demonstrate that both Entropy_2_Hex and Norm_Entropy_2_Hex achieve the highest accuracy of 90%, outperforming character-level entropy features. These findings highlight the effectiveness of byte-level entropy as a robust feature for encrypted traffic classification while mitigating packet-length dependency through normalization. This study contributes to improved darknet detection by providing a more efficient method for identifying Tor traffic. The proposed approach enhances cybersecurity efforts by supporting enforcement agencies in detecting and mitigating illicit activities within anonymous networks.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Darknet Traffic Detection with Entropy Metrics and RNN

  • Pitpimon Choorod

摘要

The darknet is a hidden part of the internet that facilitates both legal and illegal activities. Anonymity networks like Tor enable users to access the darknet while maintaining privacy, making detection challenging. Existing Tor detection methods primarily rely on flow-based or statistical features, which require multiple packets for feature extraction. However, Tor traffic closely resembles standard TLS traffic, making traditional approaches less effective. Its unique encryption mechanisms introduce distinctive data characteristics, particularly in entropy. This study presents a novel entropy-based approach to distinguishing Tor from nonTor traffic by leveraging byte-level entropy metrics, specifically Entropy_1_Hex and Entropy_2_Hex, along with their normalized versions (Norm_Entropy_1_Hex and Norm_Entropy_2_Hex), A recurrent neural network (RNN), known for its effectiveness in processing sequential data, is employed for classification. Experimental results demonstrate that both Entropy_2_Hex and Norm_Entropy_2_Hex achieve the highest accuracy of 90%, outperforming character-level entropy features. These findings highlight the effectiveness of byte-level entropy as a robust feature for encrypted traffic classification while mitigating packet-length dependency through normalization. This study contributes to improved darknet detection by providing a more efficient method for identifying Tor traffic. The proposed approach enhances cybersecurity efforts by supporting enforcement agencies in detecting and mitigating illicit activities within anonymous networks.