{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T16:54:41Z","timestamp":1771520081317,"version":"3.50.1"},"reference-count":49,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2012,11,1]],"date-time":"2012-11-01T00:00:00Z","timestamp":1351728000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["0331548 and 0534052, 0428422"],"award-info":[{"award-number":["0331548 and 0534052, 0428422"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000183","name":"Army Research Office","doi-asserted-by":"publisher","award":["W911NF-06-1-0316, W911NF-05-1-0417"],"award-info":[{"award-number":["W911NF-06-1-0316, W911NF-05-1-0417"]}],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001742","name":"United States-Israel Binational Science Foundation","doi-asserted-by":"publisher","award":["2002065"],"award-info":[{"award-number":["2002065"]}],"id":[{"id":"10.13039\/501100001742","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2012,11]]},"abstract":"<jats:p>\n            We perform a probabilistic analysis of onion routing. The analysis is presented in a black-box model of anonymous communication in the Universally Composable (UC) framework that abstracts the essential properties of onion routing in the presence of an active adversary who controls a portion of the network and knows all a priori distributions on user choices of destination. Our results quantify how much the adversary can gain in identifying users by exploiting knowledge of their probabilistic behavior. In particular, we show that, in the limit as the network gets large, a user\n            <jats:italic>u<\/jats:italic>\n            's anonymity is worst either when the other users always choose the destination\n            <jats:italic>u<\/jats:italic>\n            is least likely to visit or when the other users always choose the destination\n            <jats:italic>u<\/jats:italic>\n            chooses. This worst-case anonymity with an adversary that controls a fraction\n            <jats:italic>b<\/jats:italic>\n            of the routers is shown to be comparable to the best-case anonymity against an adversary that controls a fraction \u221a\n            <jats:italic>b<\/jats:italic>\n            .\n          <\/jats:p>","DOI":"10.1145\/2382448.2382452","type":"journal-article","created":{"date-parts":[[2012,11,29]],"date-time":"2012-11-29T15:02:27Z","timestamp":1354201347000},"page":"1-28","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":33,"title":["Probabilistic analysis of onion routing in a black-box model"],"prefix":"10.1145","volume":"15","author":[{"given":"Joan","family":"Feigenbaum","sequence":"first","affiliation":[{"name":"Yale University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aaron","family":"Johnson","sequence":"additional","affiliation":[{"name":"Yale University, University of Texas at Austin, and U.S. Naval Research Laboratory"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paul","family":"Syverson","sequence":"additional","affiliation":[{"name":"U.S. Naval Research Laboratory"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2012,11,30]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2012.32"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1314333.1314336"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-002-0128-6"},{"key":"e_1_2_1_4_1","volume-title":"Proceedings of the Ottawa Linux Symposium.","author":"Brown Z.","year":"2002"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/11535218_11"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/358549.358563"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.5555\/54235.54239"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866346"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-35691-4_40"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30114-1_21"},{"key":"e_1_2_1_12_1","volume-title":"Proceedings of the 2nd Privacy Enhancing Technologies Workshop (PET 02)","author":"D\u00edaz C."},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the 13th USENIX Security Symposium. 303--319","author":"Dingledine R."},{"key":"e_1_2_1_14_1","volume-title":"Proceedings of the 11th Financial Cryptography and Data Security Conference (FC 07)","author":"Feigenbaum J."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586137"},{"key":"e_1_2_1_16_1","unstructured":"Goldberg I. and Shostack A. 1999. Freedom 1.0 security issues and analysis. White paper Zero Knowledge Systems Inc.  Goldberg I. and Shostack A. 1999. Freedom 1.0 security issues and analysis. White paper Zero Knowledge Systems Inc."},{"key":"e_1_2_1_17_1","unstructured":"Goldberg I. and Shostack A. 2001. Freedom network 1.0 architecture and protocols. White paper Zero Knowledge Systems Inc.  Goldberg I. and Shostack A. 2001. Freedom network 1.0 architecture and protocols. White paper Zero Knowledge Systems Inc."},{"key":"e_1_2_1_18_1","volume-title":"Proceedings of the Ist International Workshop on Information Hiding. 137--150","author":"Goldschlag D. M."},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.5555\/1145948.1145953"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1655008.1655013"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1698750.1698753"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.5555\/1297689.1297694"},{"key":"e_1_2_1_23_1","volume-title":"Proceedings of the 7th International Symposium on Privacy Enhancing Technologies (PET 07)","author":"Kate A."},{"key":"e_1_2_1_24_1","volume-title":"Proceedings of the 5th Information Hiding Workshop (IH 02)","author":"Kesdogan D."},{"key":"e_1_2_1_25_1","volume-title":"Proceedings of the 2nd Information Hiding Workshop (IH 98)","author":"Kesdogan D."},{"key":"e_1_2_1_26_1","volume-title":"Proceedings of the 13th USENIX Security Symposium. 239--254","author":"Lincoln P."},{"key":"e_1_2_1_27_1","unstructured":"Loesing et al. 2011. Tor metrics portal. https:\/\/metrics.torproject.org\/.  Loesing et al. 2011. Tor metrics portal. https:\/\/metrics.torproject.org\/."},{"key":"e_1_2_1_28_1","unstructured":"Lynch N. A. 1996. Distributed Algorithms. Morgan Kaufmann Publishers.   Lynch N. A. 1996. Distributed Algorithms. Morgan Kaufmann Publishers."},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/11423409_2"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30108-0_7"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653733"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653683"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180410"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.12"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180409"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.24"},{"key":"e_1_2_1_37_1","volume-title":"Proceedings of the 7th International Symposium on Privacy Enhancing Technologies (PET 07)","author":"\u00d8verlier L."},{"key":"e_1_2_1_38_1","volume-title":"Proceedings of the Designing Privacy Enhancing Technologies: International Workshop on Design Issues in Anonymity and Unobservability. 1--9.","author":"Pfitzmann A."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/49.668972"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/290163.290168"},{"key":"e_1_2_1_41_1","volume-title":"Proceedings of the 1st European Symposium on Research in Computer Security (ESORICS 96)","author":"Schneider S."},{"key":"e_1_2_1_42_1","volume-title":"Proceedings of the 2nd Privacy Enhancing Technologies Workshop (PET 02)","author":"Serjantov A."},{"key":"e_1_2_1_43_1","first-page":"3","article-title":"Probabilistic model checking of an anonymity system","volume":"12","author":"Shmatikov V.","year":"2004","journal-title":"J. Comput. Secur."},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/1179601.1179611"},{"key":"e_1_2_1_45_1","volume-title":"Proceedings of the DARPA Information Survivability Conference and Exposition (DISCEX 00)","author":"Syverson P."},{"key":"e_1_2_1_46_1","volume-title":"Proceedings of the Designing Privacy Enhancing Technologies: International Workshop on Design Issues in Anonymity and Unobservability. 96--114","author":"Syverson P."},{"key":"e_1_2_1_47_1","volume-title":"Proceedings of the 1st World Congress on Formal Methods (FM'99)","volume":"1","author":"Syverson P. F."},{"key":"e_1_2_1_48_1","volume-title":"Proceedings of the 9th Nordic Workshop on Secure IT Systems. 85--90","author":"T\u00f3th G."},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-24638-1_18"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/1042031.1042032"}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2382448.2382452","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2382448.2382452","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:34:37Z","timestamp":1750239277000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2382448.2382452"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,11]]},"references-count":49,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2012,11]]}},"alternative-id":["10.1145\/2382448.2382452"],"URL":"https:\/\/doi.org\/10.1145\/2382448.2382452","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"value":"1094-9224","type":"print"},{"value":"1557-7406","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,11]]},"assertion":[{"value":"2011-01-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2012-05-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2012-11-30","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}