{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T02:49:51Z","timestamp":1764557391018},"reference-count":34,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"2","license":[{"start":{"date-parts":[[2017,4,1]],"date-time":"2017-04-01T00:00:00Z","timestamp":1491004800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017,4,1]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>We present PeerFlow, a system to securely load balance client traffic in Tor. Security in Tor requires that no adversary handle too much traffic. However, Tor relays are run by volunteers who cannot be trusted to report the relay bandwidths, which Tor clients use for load balancing. We show that existing methods to determine the bandwidths of Tor relays allow an adversary with little bandwidth to attack large amounts of client traffic. These methods include Tor\u2019s current bandwidth-scanning system, TorFlow, and the peer-measurement system EigenSpeed. We present an improved design called PeerFlow that uses a peer-measurement process both to limit an adversary\u2019s ability to increase his measured bandwidth and to improve accuracy. We show our system to be secure, fast, and efficient. We implement PeerFlow in Tor and demonstrate its speed and accuracy in large-scale network simulations.<\/jats:p>","DOI":"10.1515\/popets-2017-0017","type":"journal-article","created":{"date-parts":[[2017,4,6]],"date-time":"2017-04-06T10:04:34Z","timestamp":1491473074000},"page":"74-94","source":"Crossref","is-referenced-by-count":22,"title":["PeerFlow: Secure Load Balancing in Tor"],"prefix":"10.56553","volume":"2017","author":[{"given":"Aaron","family":"Johnson","sequence":"first","affiliation":[{"name":"U.S. Naval Research Laboratory"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rob","family":"Jansen","sequence":"additional","affiliation":[{"name":"U.S. Naval Research Laboratory"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nicholas","family":"Hopper","sequence":"additional","affiliation":[{"name":"University of Minnesota"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aaron","family":"Segal","sequence":"additional","affiliation":[{"name":"Yale University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paul","family":"Syverson","sequence":"additional","affiliation":[{"name":"U.S. Naval Research Laboratory"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"35752","published-online":{"date-parts":[[2017,4,4]]},"reference":[{"key":"2021040704403328703_j_popets-2017-0017_ref_001_w2aab2b8c14b1b7b1ab1ab1Aa","unstructured":"[1] https:\/\/metrics.torproject.org\/."},{"key":"2021040704403328703_j_popets-2017-0017_ref_002_w2aab2b8c14b1b7b1ab1ab2Aa","unstructured":"[2] Collector. https:\/\/collector.torproject.org\/."},{"key":"2021040704403328703_j_popets-2017-0017_ref_003_w2aab2b8c14b1b7b1ab1ab3Aa","unstructured":"[3] Shadow simulator. https:\/\/shadow.github.io."},{"key":"2021040704403328703_j_popets-2017-0017_ref_004_w2aab2b8c14b1b7b1ab1ab4Aa","unstructured":"[4] Tor directory protocol, version 3. https:\/\/gitweb.torproject.org\/torspec.git?a=blob_plain;hb=HEAD;f=dir-spec.txt."},{"key":"2021040704403328703_j_popets-2017-0017_ref_005_w2aab2b8c14b1b7b1ab1ab5Aa","unstructured":"[5] Bandwidth scanner spec. https:\/\/gitweb.torproject.org\/torflow.git\/blob_plain\/HEAD:\/NetworkScanners\/BwAuthority\/README.spec.txt."},{"key":"2021040704403328703_j_popets-2017-0017_ref_006_w2aab2b8c14b1b7b1ab1ab6Aa","doi-asserted-by":"crossref","unstructured":"[6] Olivier Baudron, Pierre-Alain Fouque, David Pointcheval, Jacques Stern, and Guillaume Poupard. Practical multicandidate election system. In Ajay D. Kshemkalyani and Nir Shavit, editors, Proceedings of the Twentieth Annual ACM Symposium on Principles of Distributed Computing, PODC 2001, Newport, Rhode Island, USA, August 26-29, 2001, pages 274\u2013283. ACM, 2001.","DOI":"10.1145\/383962.384044"},{"key":"2021040704403328703_j_popets-2017-0017_ref_007_w2aab2b8c14b1b7b1ab1ab7Aa","doi-asserted-by":"crossref","unstructured":"[7] Kevin Bauer, Damon McCoy, Dirk Grunwald, Tadayoshi Kohno, and Douglas Sicker. Low-resource routing attacks against Tor. In ACM WPES, 2007.","DOI":"10.1145\/1314333.1314336"},{"key":"2021040704403328703_j_popets-2017-0017_ref_008_w2aab2b8c14b1b7b1ab1ab8Aa","doi-asserted-by":"crossref","unstructured":"[8] Alex Biryukov, Ivan Pustogarov, and Ralf-Philipp Weinmann. Trawling for Tor hidden services: Detection, measurement, deanonymization. In IEEE S&P, 2013.","DOI":"10.1109\/SP.2013.15"},{"key":"2021040704403328703_j_popets-2017-0017_ref_009_w2aab2b8c14b1b7b1ab1ab9Aa","doi-asserted-by":"crossref","unstructured":"[9] Ronald Cramer, Ivan Damg\u00e5rd, and Berry Schoenmakers. Proofs of partial knowledge and simplified design of witness hiding protocols. In Yvo Desmedt, editor, Advances in Cryptology - CRYPTO \u201994, 14th Annual International Cryptology Conference, Santa Barbara, California, USA, August 21-25, 1994, Proceedings, volume 839 of Lecture Notes in Computer Science, pages 174\u2013187. Springer, 1994.","DOI":"10.1007\/3-540-48658-5_19"},{"key":"2021040704403328703_j_popets-2017-0017_ref_010_w2aab2b8c14b1b7b1ab1ac10Aa","doi-asserted-by":"crossref","unstructured":"[10] Ivan Damg\u00e5rd and Mads Jurik. A generalisation, a simplification and some applications of paillier\u2019s probabilistic public-key system. In Kwangjo Kim, editor, Public Key Cryptography, 4th International Workshop on Practice and Theory in Public Key Cryptography, PKC 2001, Cheju Island, Korea, February 13-15, 2001, Proceedings, volume 1992 of Lecture Notes in Computer Science, pages 119\u2013136. Springer, 2001.","DOI":"10.1007\/3-540-44586-2_9"},{"key":"2021040704403328703_j_popets-2017-0017_ref_011_w2aab2b8c14b1b7b1ab1ac11Aa","unstructured":"[11] Ivan Damg\u00e5rd and Mads Jurik. A length-flexible threshold cryptosystem with applications. In Reihaneh Safavi-Naini and Jennifer Seberry, editors, Information Security and Privacy, 8th Australasian Conference, ACISP 2003, Wollongong, Australia, July 9-11, 2003, Proceedings, volume 2727 of Lecture Notes in Computer Science, pages 350\u2013364. Springer, 2003."},{"key":"2021040704403328703_j_popets-2017-0017_ref_012_w2aab2b8c14b1b7b1ab1ac12Aa","doi-asserted-by":"crossref","unstructured":"[12] Roger Dingledine, Nick Mathewson, and Paul Syverson. Tor: The second-generation onion router. In USENIX Security, 2004.","DOI":"10.21236\/ADA465464"},{"key":"2021040704403328703_j_popets-2017-0017_ref_013_w2aab2b8c14b1b7b1ab1ac13Aa","doi-asserted-by":"crossref","unstructured":"[13] Cynthia Dwork. Differential privacy. In International Colloquium on Automata, Languages and Programming, 2006.","DOI":"10.1007\/11787006_1"},{"key":"2021040704403328703_j_popets-2017-0017_ref_014_w2aab2b8c14b1b7b1ab1ac14Aa","unstructured":"[14] Nathan Evans, Roger Dingledine, and Christian Grothoff. A practical congestion attack on Tor using long paths. In USENIX Security, 2009."},{"key":"2021040704403328703_j_popets-2017-0017_ref_015_w2aab2b8c14b1b7b1ab1ac15Aa","doi-asserted-by":"crossref","unstructured":"[15] Pierre-Alain Fouque, Guillaume Poupard, and Jacques Stern. Sharing decryption in the context of voting or lotteries. In Yair Frankel, editor, Financial Cryptography, 4th International Conference, FC 2000 Anguilla, British West Indies, February 20-24, 2000, Proceedings, volume 1962 of Lecture Notes in Computer Science, pages 90\u2013104. Springer, 2000.","DOI":"10.1007\/3-540-45472-1_7"},{"key":"2021040704403328703_j_popets-2017-0017_ref_016_w2aab2b8c14b1b7b1ab1ac16Aa","unstructured":"[16] David Goulet, Aaron Johnson, George Kadianakis, and Karsten Loesing. Hidden-service statistics reported by relays. Technical Report 2015-04-001, The Tor Project, Inc., April 2015."},{"key":"2021040704403328703_j_popets-2017-0017_ref_017_w2aab2b8c14b1b7b1ab1ac17Aa","doi-asserted-by":"crossref","unstructured":"[17] Andreas Haeberlen, Petr Kouznetsov, and Peter Druschel. Peerreview: Practical accountability for distributed systems. In SOSP, 2007.","DOI":"10.1145\/1294261.1294279"},{"key":"2021040704403328703_j_popets-2017-0017_ref_018_w2aab2b8c14b1b7b1ab1ac18Aa","doi-asserted-by":"crossref","unstructured":"[18] Nicholas Hopper, Eugene Y. Vasserman, and Eric Chan-Tin. How much anonymity does network latency leak? TISSEC, 13(2), February 2010.","DOI":"10.1145\/1698750.1698753"},{"key":"2021040704403328703_j_popets-2017-0017_ref_019_w2aab2b8c14b1b7b1ab1ac19Aa","unstructured":"[19] Rob Jansen, Kevin Bauer, Nicholas Hopper, and Roger Dingledine. Methodically modeling the Tor network. In CSET, 2012."},{"key":"2021040704403328703_j_popets-2017-0017_ref_020_w2aab2b8c14b1b7b1ab1ac20Aa","unstructured":"[20] Rob Jansen, John Geddes, Chris Wacek, Micah Sherr, and Paul Syverson. Never been KIST: Tor\u2019s congestion management blossoms with kernel-informed socket transport. In USENIX Security, 2014."},{"key":"2021040704403328703_j_popets-2017-0017_ref_021_w2aab2b8c14b1b7b1ab1ac21Aa","doi-asserted-by":"crossref","unstructured":"[21] Rob Jansen and Nicholas Hopper. Shadow: Running Tor in a box for accurate and efficient experimentation. In NDSS, 2012.","DOI":"10.21236\/ADA559181"},{"key":"2021040704403328703_j_popets-2017-0017_ref_022_w2aab2b8c14b1b7b1ab1ac22Aa","unstructured":"[22] Rob Jansen, Aaron Johnson, and Paul Syverson. LIRA: Lightweight incentivized routing for anonymity. In NDSS, 2013."},{"key":"2021040704403328703_j_popets-2017-0017_ref_023_w2aab2b8c14b1b7b1ab1ac23Aa","unstructured":"[23] Rob Jansen, Andrew Miller, Paul Syverson, and Bryan Ford. From onions to shallots: Rewarding Tor relays with TEARS. In HotPETs, 2014."},{"key":"2021040704403328703_j_popets-2017-0017_ref_024_w2aab2b8c14b1b7b1ab1ac24Aa","doi-asserted-by":"crossref","unstructured":"[24] Aaron Johnson, Chris Wacek, Rob Jansen, Micah Sherr, and Paul Syverson. Users get routed: Traffic correlation on Tor by realistic adversaries. In ACM CCS, 2013.","DOI":"10.1145\/2508859.2516651"},{"key":"2021040704403328703_j_popets-2017-0017_ref_025_w2aab2b8c14b1b7b1ab1ac25Aa","doi-asserted-by":"crossref","unstructured":"[25] Ghassan Karame, David Gubler, and Srdjan Capkun. On the security of bottleneck bandwidth estimation techniques. In SecureComm. 2009.","DOI":"10.1007\/978-3-642-05284-2_8"},{"key":"2021040704403328703_j_popets-2017-0017_ref_026_w2aab2b8c14b1b7b1ab1ac26Aa","unstructured":"[26] Mike Perry. TorFlow: Tor network analysis. In HotPETs, 2009."},{"key":"2021040704403328703_j_popets-2017-0017_ref_027_w2aab2b8c14b1b7b1ab1ac27Aa","unstructured":"[27] Robin Snader. Path Selection for Performance- and Security-Improved Onion Routing. PhD thesis, U. of I. at Urbana-Champaign, 2009."},{"key":"2021040704403328703_j_popets-2017-0017_ref_028_w2aab2b8c14b1b7b1ab1ac28Aa","unstructured":"[28] Robin Snader and Nikita Borisov. Eigenspeed: Secure peer-to-peer bandwidth evaluation. In IPTPS, 2009."},{"key":"2021040704403328703_j_popets-2017-0017_ref_029_w2aab2b8c14b1b7b1ab1ac29Aa","doi-asserted-by":"crossref","unstructured":"[29] Robin Snader and Nikita Borisov. Improving security and performance in the Tor network through tunable path selection. TDSC, 8(5):728\u2013741, September 2011.","DOI":"10.1109\/TDSC.2010.40"},{"key":"2021040704403328703_j_popets-2017-0017_ref_030_w2aab2b8c14b1b7b1ab1ac30Aa","doi-asserted-by":"crossref","unstructured":"[30] R. Suselbeck, G. Schiele, P. Komarnicki, and C. Becker. Efficient bandwidth estimation for peer-to-peer systems. In IEEE P2P, 2011.","DOI":"10.1109\/P2P.2011.6038656"},{"key":"2021040704403328703_j_popets-2017-0017_ref_031_w2aab2b8c14b1b7b1ab1ac31Aa","unstructured":"[31] Fabrice Thill. Hidden Service Tracking Detection and Bandwidth Cheating in Tor Anonymity Network. PhD thesis, Univ. Luxembourg, 2014."},{"key":"2021040704403328703_j_popets-2017-0017_ref_032_w2aab2b8c14b1b7b1ab1ac32Aa","unstructured":"[32] Tao Wang, Xiang Cai, Rishab Nithyanand, Rob Johnson, and Ian Goldberg. Effective attacks and provable defenses for website fingerprinting. In USENIX Security, 2014."},{"key":"2021040704403328703_j_popets-2017-0017_ref_033_w2aab2b8c14b1b7b1ab1ac33Aa","doi-asserted-by":"crossref","unstructured":"[33] Tao Wang and Ian Goldberg. Improved website fingerprinting on Tor. In ACM WPES, 2013.","DOI":"10.1145\/2517840.2517851"},{"key":"2021040704403328703_j_popets-2017-0017_ref_034_w2aab2b8c14b1b7b1ab1ac34Aa","doi-asserted-by":"crossref","unstructured":"[34] Matthew Wright, Micah Adler, Brian Neil Levine, and Clay Shields. The predecessor attack: An analysis of a threat to anonymous communications systems. TISSEC, 4(7):489\u2013522, November 2004.","DOI":"10.1145\/1042031.1042032"}],"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/content.sciendo.com\/view\/journals\/popets\/2017\/2\/article-p74.xml","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.sciendo.com\/article\/10.1515\/popets-2017-0017","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,23]],"date-time":"2023-08-23T01:13:37Z","timestamp":1692753217000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2017\/popets-2017-0017.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,4,1]]},"references-count":34,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2017,4,4]]},"published-print":{"date-parts":[[2017,4,1]]}},"alternative-id":["10.1515\/popets-2017-0017"],"URL":"https:\/\/doi.org\/10.1515\/popets-2017-0017","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,4,1]]}}}