External Dynamic List and Middle Relay Tor for Internet Access Control in an Enterprise Network
William-Rogelio Marchand-Niño, Jose-Manuel Bravo-Rengifo · 2023
The use of Tor Browser in an organization allows network users to bypass Internet access controls without being detected, in addition, onion services may contain malware or be used to distribute it, which could negatively affect the organization’s reputation. This research aims to evaluate the effectiveness of configuring the External Dynamic List (EDL) mechanism and a Middle Relay Tor (MRT) combined for Internet access control in an enterprise network versus using both techniques independently. Three scenarios or configurations were deployed, Tor’s EDLs directories were also used, and a VPS as a middle relay that captures the IP addresses of the bridges that establish circuits with the same VPS in order to add them to the firewall’s blacklist. The operation of the scenarios was automated with scripts in Python. As part of the results, it was found that 67% of the total connection attempts to the Tor network were blocked by the firewall with EDL&MRT combined configuration, compared to 1% average if each configuration is used independently. The impact of the configurations made in the firewall on Internet access with a traditional browser (Google Chrome) was also contrasted under the assumption of normal user behavior, and it was obtained as a result that only 3.0% of the connection attempts were unsuccessful.