Anonymous Communication designs such as Tor build their security upon distributing the trust in many volunteers running relays in many locations globally. In practice, it leads to a heterogeneous network in which many versions of the same Tor software exist, with a different set of protocol features. Because of the heterogeneous aspect of the network, the maintainers employ forward-compatible protocol design strategies to maintain network extensibility. These strategies aim to guarantee that different versions of the Tor software interact without unrecoverable errors. In this work, we cast the protocol tolerance enabled with forward-compatible protocol considerations as a fundamental security issue. Despite being beneficial for the developers, we argue that protocol tolerance is the cause of many strong attacks against Tor in the past fifteen years. To address this issue, we propose FAN for Flexible Anonymous Network, a new software architecture for volunteer-based distributed networks that shifts the dependence away from protocol tolerance without losing the ability for the developers to ensure the continuous evolution of their software. We realize an implementation, evaluate the overheads and, experiment with several of FAN's benefits to defend against a severe attack still applicable to Tor today.
翻译:匿名通信设计(如Tor)通过将信任分散到全球众多志愿者运行的节点中构建安全性。实践中,这导致了一个异构网络——其中存在同一Tor软件的多个版本,每个版本具有不同的协议功能集。由于网络的异构特性,维护者采用前向兼容的协议设计策略以维持网络的可扩展性。这些策略旨在确保不同版本的Tor软件在交互时不会产生不可恢复的错误。在本工作中,我们将由前向兼容协议设计引发的协议容错性定义为一个基本安全问题。尽管这对开发者有益,但我们认为协议容错性是过去十五年间针对Tor的许多强攻击的根本原因。为解决此问题,我们提出FAN(灵活匿名网络)——一种面向志愿者分布式网络的新型软件架构,该架构在无需开发者丧失软件持续演进能力的前提下,将依赖性从协议容错中剥离。我们实现了原型系统,评估了其开销,并通过实验验证了FAN在防御当前仍适用于Tor的严重攻击方面的多重优势。