Refining Node Similarity Analysis: An Optimized Nearest-Neighbor Ranking Algorithm
Jiaqi Sui, Wei Guo, Xin Shi, Shuai Zhang, Hongchao Hu · 2024
As The Onion Router (Tor) becomes increasingly prevalent, attackers have initiated Sybil attacks by controlling a plethora of malicious relay nodes, severely compromising user privacy. Thus, the identification of malicious Sybil nodes is crucial for ensuring the security of the Tor network. Previous studies suggested that Sybil nodes tend to have similar configuration and close uptime, leading to the design of the Nearest-neighbor ranking algorithm for analyzing the similarity between relay nodes. This was followed by further manual analysis to sift Sybil nodes from similar ones. However, the algorithm's simplistic approach of treating nodes' basic information uniformly as strings resulted in less accurate analysis of relay node similarity. To tackle this issue, this paper introduces an optimized Nearest-neighbor ranking algorithm based on comprehensive node similarity scores. This algorithm thoroughly accounts for the differences in node configuration information and employs various methods to calculate the similarity scores between each parameter. Using the final comprehensive node similarity scores, the algorithm sorts the list of relay nodes to identify similar ones. Upon validation, the optimized algorithm has demonstrated higher accuracy in recognizing similar nodes, facilitates subsequent manual analysis of malicious Sybil nodes.