Impact Analysis of Sybil Attacks in the Tor Network
摘要
Tor, the most widely used anonymity network with around 2 million users, relies on volunteer-operated relays to route traffic through circuits while preserving anonymity. However, it faces a significant challenge, the diversity problem, where power is concentrated among a few dominant relay operators. It increases the risk of Sybil attacks-where attackers introduce multiple relays without clear attribution, potentially enabling traffic monitoring and de-anonymization. This paper examines the diversity problem and Sybil attack implications through data aggregation and simulations, revealing significant vulnerabilities. Notably, the top 10 relay families control over 50% of exit traffic, and an attacker operating two separate relay families with 120 and 178 relays could deanonymize 0.8% of all circuits. Additionally, combining Sybil attacks with bandwidth inflation could allow an attacker to observe up to 13.44% of exit and 6.45% of entry traffic for just $400 per month. The study also highlights weaknesses in Tor’s Sybil detection mechanisms, emphasizing the need for mitigation strategies to safeguard user privacy.