Knock-Knock: De-Anonymise Hidden Services by Exploiting Service Answer Vulnerability

Qingfeng Zhang, Muqian Chen, Xuebin Wang, Can Zhao, Qingyun Liu, Jinqiao Shi · 2024

The hidden service, devised by the Tor Project, serves to protect receiver anonymity. However, to address the potential abuse of hidden services, this paper introduces the “Knock-Knock attack,” a novel de-anonymization method that utilizes watermark to enable an attacker to conduct an attack with control over only the client and the guard relays. The key of our approach is manipulating the number of RELAY_COMMAND_BEGIN cells and RELAY_COMMAND_CONNECTED cells to construct flexible and robust watermarks during the Tor protocol handshake, thus facilitating parallel de-anonymization of hidden services while remaining insensitive to the network state. Empirical experiments demonstrate that our attack boasts a 100% true positive rate and 0% false positive rate. Additionally, we propose a theoretical framework to guide the optimal encoding form of watermark, leading to a notable 3.6 times improvement in speed compared to prior works. Lastly, we present a method to mitigate watermark attacks and report the design flaw to the Tor Project.

Read the paper · More papers on PaperTik