Skip to main content
QUICK REVIEW

[论文解读] When A Small Leak Sinks A Great Ship: Deanonymizing Tor Hidden Service Users Through Bitcoin Transactions Analysis

Husam Al Jawaheri, Mashael Al Sabah|arXiv (Cornell University)|Jan 23, 2018
Internet Traffic Analysis and Secure E-voting参考文献 18被引用 15
一句话总结

本文证明,通过关联社交媒体、比特币区块链交易和洋葱网站的公开数据,可以对使用比特币支付的Tor隐藏服务用户实施去匿名化攻击。通过将比特币地址与在线身份关联并追踪交易,作者成功将125名用户与20个隐藏服务(包括The Pirate Bay和Silk Road等高调目标)关联起来,证明比特币的假名机制不足以实现事后匿名性。

ABSTRACT

With the rapid increase of threats on the Internet, people are continuously seeking privacy and anonymity. Services such as Bitcoin and Tor were introduced to provide anonymity for online transactions and Web browsing. Due to its pseudonymity model, Bitcoin lacks retroactive operational security, which means historical pieces of information could be used to identify a certain user. We investigate the feasibility of deanonymizing users of Tor hidden services who rely on Bitcoin as a payment method by exploiting public information leaked from online social networks, the Blockchain, and onion websites. This, for example, allows an adversary to link a user with @alice Twitter address to a Tor hidden service with private.onion address by finding at least one past transaction in the Blockchain that involves their publicly declared Bitcoin addresses. To demonstrate the feasibility of this deanonymization attack, we carried out a real-world experiment simulating a passive, limited adversary. We crawled 1.5K hidden services and collected 88 unique Bitcoin addresses. We then crawled 5B tweets and 1M BitcoinTalk forum pages and collected 4.2K and 41K unique Bitcoin addresses, respectively. Each user address was associated with an online identity along with its public profile information. By analyzing the transactions in the Blockchain, we were able to link 125 unique users to 20 Tor hidden services, including sensitive ones, such as The Pirate Bay and Silk Road. We also analyzed two case studies in detail to demonstrate the implications of the resulting information leakage on user anonymity. In particular, we confirm that Bitcoin addresses should always be considered exploitable, as they can be used to deanonymize users retroactively. This is especially important for Tor hidden service users who actively seek and expect privacy and anonymity.

研究动机与目标

  • 调查利用比特币支付的Tor隐藏服务用户去匿名化的可行性。
  • 研究如何结合社交媒体、区块链数据和洋葱网站的公开信息来破坏用户匿名性。
  • 评估比特币假名模型带来的事后去匿名化风险。
  • 展示信息泄露对隐私保护系统(如Tor和比特币)的实际影响。

提出的方法

  • 爬取1.5K个Tor隐藏服务,收集88个用于支付的唯一比特币地址。
  • 从50亿条推文和100万条BitcoinTalk论坛页面中收集4.2K个比特币地址。
  • 利用社交媒体和论坛的公开资料,将每个比特币地址映射到一个在线身份。
  • 通过追踪比特币区块链中的交易,将用户身份与特定隐藏服务关联。
  • 执行被动、有限的敌手模拟,评估现实可行性。
  • 开展两个详细案例研究,分析去匿名化对用户隐私的影响。

实验结果

研究问题

  • RQ1比特币交易数据能否用于对接受比特币支付的Tor隐藏服务用户实施去匿名化?
  • RQ2社交媒体和论坛的公开信息在多大程度上可被用于将比特币地址与真实身份关联?
  • RQ3区块链分析与在线身份关联的结合在破坏用户匿名性方面有多有效?
  • RQ4通过被动、低资源攻击实现隐藏服务用户去匿名化的现实可行性如何?

主要发现

  • 本研究仅使用公开数据和区块链分析,成功将125名独立用户与20个Tor隐藏服务关联。
  • 包括The Pirate Bay和Silk Road在内的高调隐藏服务通过该方法被成功去匿名化。
  • 比特币地址被证实可被用于事后去匿名化,从而破坏其假名模型的安全性。
  • 社交媒体和论坛上的公开披露显著增加了去匿名化风险,使身份与比特币地址产生关联。
  • 该攻击仅需极少资源即可实施,模拟了无直接访问用户系统之被动敌手。
  • 结果表明,比特币地址在长期匿名性方面绝不可靠,尤其在Tor隐藏服务等隐私敏感场景中。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。