Counting daily bridge users
Karsten Loesing · 2012
As part of the Tor Metrics Project, we want to learn how many people use the Tor network on a daily basis. Counting users in an anonymity network is, obviously, a difficult task for which we cannot collect too sensitive usage data. We came up with a privacypreserving approach for estimating directly connecting user numbers by counting requests to the directory mirrors and deriving approximate user numbers from there. In this report we describe a modified approach for estimating the number of users connecting via bridges by evaluating directory requests made to bridges. We compare this new approach to our current approach that estimates bridge user numbers from total unique IP addresses seen at bridges. We think that results from the new approach are closer to reality, even though that means there are significantly fewer daily bridge users than originally expected. 1 Introduction to our new approach to count bridge users In this report we describe a new approach for estimating the number of daily users connecting to the Tor network via a bridge. This new approach uses counts of directory requests made to bridges as its main data sources. This is similar to how we estimate daily directly connecting users that connect to the Tor network via a non-bridge relay. Our current approach for estimating daily bridge users is to count unique IP addresses of connecting clients at bridges. We refer to our earlier report [1] for an overview of estimating user numbers in the Tor network. We estimate daily bridge users by first summing up directory requests per day reported by bridges (Section 2). We extrapolate these reported requests to the expected total number of directory requests in the network (Section 3). We then assume that there is an average number of 10 directory requests that every client makes per day and derive daily user numbers by dividing by that average number (Section 4). We further derive users per country by including country information of connecting IP addresses (Section 5). There are at least two ways to remove unwanted artifacts from results: we may have to ignore reports from bridges that have been running as non-bridge relays and that might still report directly connecting users (Section 6); and we may need to ignore days when there were problems with the consensus process, leading to an increase in directory requests which is likely not caused by an actual increase in users (Section 7).