{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T15:24:20Z","timestamp":1783437860390,"version":"3.54.6"},"publisher-location":"Singapore","reference-count":26,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789811692284","type":"print"},{"value":"9789811692291","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Tor exit relays are operated by volunteers and the trustworthiness of Tor exit relays need to be revisited in a long-term manner. In this paper, we monitored the Tor network by developing a fast and distributed exit relay scanner (ExitSniffer) to probe all exit relays over a period of 16\u00a0months continuously, seeking to expose the anomalous binding relationship phenomena of exit routers simply by comparing the returnIP and consensusIP. We totally find 1983 malicious exit relays which average contribute 10.12% bandwidth of total Tor exit relays bandwidth monthly, resulting tremendous threaten for Tor user\u2019s anonymity according to the current path-relay selecting algorithm. There exits two types of anomalous binding relationship consists 35 exit relay families, with different size ranging from 2 to 230, which are neither announced in the consensus document or detected by the Tor network.<\/jats:p>","DOI":"10.1007\/978-981-16-9229-1_6","type":"book-chapter","created":{"date-parts":[[2022,1,21]],"date-time":"2022-01-21T12:03:56Z","timestamp":1642766636000},"page":"93-109","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["ExitSniffer: Towards Comprehensive Security Analysis of\u00a0Anomalous Binding Relationship of\u00a0Exit Routers"],"prefix":"10.1007","author":[{"given":"Qingfeng","family":"Zhang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xuebin","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jinqiao","family":"Shi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Meiqi","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yue","family":"Gao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Can","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,1,21]]},"reference":[{"key":"6_CR1","unstructured":"The number of exit nodes. https:\/\/metrics.torproject.org\/relayflags.html. Accessed 18 Aug 2021"},{"key":"6_CR2","doi-asserted-by":"crossref","unstructured":"Dingledine, R., Mathewson, N., Syverson, P.: Tor: the second-generation onion router. In: USENIX Security. USENIX Association (2004)","DOI":"10.21236\/ADA465464"},{"key":"6_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1007\/11745853_14","volume-title":"Public Key Cryptography - PKC 2006","author":"DJ Bernstein","year":"2006","unstructured":"Bernstein, D.J.: Curve25519: new Diffie-Hellman speed records. In: Yung, M., Dodis, Y., Kiayias, A., Malkin, T. (eds.) PKC 2006. LNCS, vol. 3958, pp. 207\u2013228. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11745853_14"},{"key":"6_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"245","DOI":"10.1007\/978-3-642-13241-4_22","volume-title":"Communications and Multimedia Security","author":"M Huber","year":"2010","unstructured":"Huber, M., Mulazzani, M., Weippl, E.: Tor HTTP usage and information leakage. In: De Decker, B., Schaum\u00fcller-Bichl, I. (eds.) CMS 2010. LNCS, vol. 6109, pp. 245\u2013255. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-13241-4_22"},{"key":"6_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"251","DOI":"10.1007\/3-540-45748-8_24","volume-title":"Peer-to-Peer Systems","author":"JR Douceur","year":"2002","unstructured":"Douceur, J.R.: The Sybil attack. In: Druschel, P., Kaashoek, F., Rowstron, A. (eds.) IPTPS 2002. LNCS, vol. 2429, pp. 251\u2013260. Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/3-540-45748-8_24"},{"key":"6_CR6","unstructured":"Marlinspike, M.: Sslstrip. http:\/\/www.thoughtcrime.org\/software\/sslstrip\/"},{"key":"6_CR7","unstructured":"Ryan, P.: Security expert used tor to collect government e-mail passwords (2007)"},{"key":"6_CR8","unstructured":"TOR exit-node doing MITM attacks. http:\/\/www.teamfurry.com\/wordpress\/2007\/11\/20\/tor-exit-node-doing-mitm-attacks\/"},{"key":"6_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"304","DOI":"10.1007\/978-3-319-08506-7_16","volume-title":"Privacy Enhancing Technologies","author":"P Winter","year":"2014","unstructured":"Winter, P., et al.: Spoiled onions: exposing malicious tor exit relays. In: De Cristofaro, E., Murdoch, S.J. (eds.) PETS 2014. LNCS, vol. 8555, pp. 304\u2013331. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-08506-7_16"},{"key":"6_CR10","unstructured":"The Tor Project. Tor Metrics. https:\/\/metrics.torproject.org\/"},{"key":"6_CR11","unstructured":"Winter, P., et al.: Identifying and characterizing Sybils in the Tor network. ArXiv abs\/1602.07787 (2016)"},{"key":"6_CR12","unstructured":"How Malicious Tor Relays are Exploiting Users in 2020 (2020). https:\/\/nusenu.medium.com\/how-malicious-tor-relays-are-exploiting-users-in-2020-part-i-1097575c0cac"},{"key":"6_CR13","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Zhou, W., Sherr, M.: Bypassing tor exit blocking with exit bridge onion services. In: ACM Conference on Computer and Communications Security (CCS) (2020)","DOI":"10.1145\/3372297.3417245"},{"key":"6_CR14","unstructured":"The Tor Project. Stem Docs (2013). https:\/\/stem.torproject.org"},{"key":"6_CR15","doi-asserted-by":"publisher","first-page":"166","DOI":"10.2478\/popets\/20190025","volume":"2","author":"H Hanley","year":"2019","unstructured":"Hanley, H., Sun, Y., Wagh, S., Mittal, P.: DPSelect: a differential privacy based guard relay selection algorithm for tor. Proc. Priv. Enhancing Technol. 2, 166\u2013186 (2019). https:\/\/doi.org\/10.2478\/popets\/20190025","journal-title":"Proc. Priv. Enhancing Technol."},{"key":"6_CR16","unstructured":"The Tor Project. Relays with Exit, Fast, Guard, Stable, and HSDir flags (2013). https:\/\/metrics.torproject.org\/network.html"},{"key":"6_CR17","first-page":"127","volume":"2016","author":"A Sanatinia","year":"2016","unstructured":"Sanatinia, A., Noubir, G.: Honey onions: a framework for characterizing and identifying misbehaving Tor HSDirs. IEEE Conf. Commun. Netw. Secur. (CNS) 2016, 127\u2013135 (2016)","journal-title":"IEEE Conf. Commun. Netw. Secur. (CNS)"},{"key":"6_CR18","unstructured":"Chen, M., Wang, X., Shi, J., Yue, G., Gan, Z.: Towards comprehensive secuity analysis of family phenomenon of Tor hidden service. In: ICICS 2019 (2019)"},{"key":"6_CR19","doi-asserted-by":"crossref","unstructured":"Hodges, J., Jackson, C., Barth, A.: RFC 6797: HTTP Strict Transport Security (HSTS) (2012). https:\/\/tools.ietf.org\/html","DOI":"10.17487\/rfc6797"},{"key":"6_CR20","unstructured":"Alexa: The top 500 sites on the web (2013). http:\/\/www.alexa.com\/topsites"},{"key":"6_CR21","doi-asserted-by":"crossref","unstructured":"Singh, R., et al.: Characterizing the nature and dynamics of tor exit blocking. In: USENIX Security Symposium (USENIX) (2017)","DOI":"10.1145\/3232755.3232786"},{"key":"6_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"167","DOI":"10.1007\/978-3-540-75551-7_11","volume-title":"Privacy Enhancing Technologies","author":"SJ Murdoch","year":"2007","unstructured":"Murdoch, S.J., Zieli\u0144ski, P.: Sampled traffic analysis by internet-exchange-level adversaries. In: Borisov, N., Golle, P. (eds.) PET 2007. LNCS, vol. 4776, pp. 167\u2013183. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-75551-7_11"},{"key":"6_CR23","doi-asserted-by":"crossref","unstructured":"Nasr, M., Bahramali, A., Houmansadr, A.: Deepcorr: strong flow correlation attacks on Tor using deep learning. In: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, pp. 1962\u20131976 (2018)","DOI":"10.1145\/3243734.3243824"},{"key":"6_CR24","doi-asserted-by":"crossref","unstructured":"Ling, Z., Luo, J., Yu, W., et al.: A new cell counter based attack against Tor. In: Proceedings of the 16th ACM conference on Computer and Communications Security, pp. 578\u2013589 (2009)","DOI":"10.1145\/1653662.1653732"},{"issue":"1","key":"6_CR25","doi-asserted-by":"publisher","first-page":"67","DOI":"10.1016\/j.future.2010.04.007","volume":"27","author":"X Wang","year":"2011","unstructured":"Wang, X., Luo, J., Yang, M., et al.: A potential HTTP-based application-level attack against Tor. Futur. Gener. Comput. Syst. 27(1), 67\u201377 (2011)","journal-title":"Futur. Gener. Comput. Syst."},{"key":"6_CR26","doi-asserted-by":"crossref","unstructured":"Akhoondi, M., Yu, C., Madhyastha, H.V.: LASTor: a low-latency AS-aware Tor client. In: 2012 IEEE Symposium on Security and Privacy, pp. 476\u2013490. IEEE (2012)","DOI":"10.1109\/SP.2012.35"}],"container-title":["Communications in Computer and Information Science","Cyber Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-16-9229-1_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,21]],"date-time":"2022-04-21T14:21:20Z","timestamp":1650550880000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-16-9229-1_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9789811692284","9789811692291"],"references-count":26,"URL":"https:\/\/doi.org\/10.1007\/978-981-16-9229-1_6","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"value":"1865-0929","type":"print"},{"value":"1865-0937","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"21 January 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CNCERT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China Cyber Security Annual Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Beijing","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 July 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 July 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"cncert2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/conf.cert.org.cn","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}