{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/34363"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/34363","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Protecting anonymity in the presence of autonomous system and internet exchange level adversaries","abstract":"This thesis analyzes the threat of autonomous system (AS) and Internet exchange (IX) level adversaries on Tor, currently the most widely deployed and used anonymity overlay network. Of particular interest is the possibility of a single AS or IX point observing both the path from the client to the entry node and the path from the exit node to the nal destination. Experimental results indicate that a non-trivial number of circuits are vulnerable to such compromise. A novel AS-level path prediction algorithm is developed in order to allow the client to choose paths without vulnerabilities. The path prediction algorithm sacri ces some accuracy in the top path prediction in order to decrease the hardware requirements necessary to predict AS-level paths and is simple enough to run on standard client hardware. We validate the accuracy of the path predictor rst compared to classical path prediction algorithms, then compared to traceroute data taken from Planet Lab. The simulator predicts paths with similar sets of ASes and links nding 90% of the actual ASes seen in the traceroute data. The e ects of choosing paths utilizing the new path predictions is then investigated to nd that load balancing is adversely a ected. The entropy loss due to the new path selection method is also investigated, speci cally the entropy of the client from an adversary observing the exit/destination path. We nd that choosing paths with our new path selection algorithm results in minimal entropy loss. Overall, the results demonstrate that the new path simulator is a lightweight solution to defend against AS and IX-level compromise of anonymous communication paths on the Internet and should be considered for deployment to maintain the privacy guarantees of such systems.","abstract_html":"This thesis analyzes the threat of autonomous system (AS) and Internet exchange (IX) level adversaries on Tor, currently the most widely deployed and used anonymity overlay network. Of particular interest is the possibility of a single AS or IX point observing both the path from the client to the entry node and the path from the exit node to the nal destination. Experimental results indicate that a non-trivial number of circuits are vulnerable to such compromise. A novel AS-level path prediction algorithm is developed in order to allow the client to choose paths without vulnerabilities. The path prediction algorithm sacri ces some accuracy in the top path prediction in order to decrease the hardware requirements necessary to predict AS-level paths and is simple enough to run on standard client hardware. We validate the accuracy of the path predictor rst compared to classical path prediction algorithms, then compared to traceroute data taken from Planet Lab. The simulator predicts paths with similar sets of ASes and links nding 90% of the actual ASes seen in the traceroute data. The e ects of choosing paths utilizing the new path predictions is then investigated to nd that load balancing is adversely a ected. The entropy loss due to the new path selection method is also investigated, speci cally the entropy of the client from an adversary observing the exit/destination path. We nd that choosing paths with our new path selection algorithm results in minimal entropy loss. Overall, the results demonstrate that the new path simulator is a lightweight solution to defend against AS and IX-level compromise of anonymous communication paths on the Internet and should be considered for deployment to maintain the privacy guarantees of such systems.","abstract_has_math":false,"creators":["Juen, Joshua"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Borisov, Nikita"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2012,"date_issued":"2012-09-18T21:13:21Z","date_published":"2012-09-18T21:13:21Z","updated_at":"2026-07-22T22:25:31Z","subjects":["Anonymity","Autonomous Overlay Networks","Privacy","Tor","Networking"],"languages":["en"],"rights":["Copyright 2012 Joshua Paul Joseph Juen"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/34363","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Borisov, Nikita"]},{"key":"dc:creator","label":"Author","values":["Juen, Joshua"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2012-09-18T21:13:21Z","2012-08"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Anonymity","Autonomous Overlay Networks","Privacy","Tor","Networking"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2012 Joshua Paul Joseph Juen"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/34363"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["This thesis analyzes the threat of autonomous system (AS) and Internet exchange (IX) level adversaries on Tor, currently the most widely deployed and used anonymity overlay network. Of particular interest is the possibility of a single AS or IX point observing both the path from the client to the entry node and the path from the exit node to the nal destination. Experimental results indicate that a non-trivial number of circuits are vulnerable to such compromise. A novel AS-level path prediction algorithm is developed in order to allow the client to choose paths without vulnerabilities. The path prediction algorithm sacri ces some accuracy in the top path prediction in order to decrease the hardware requirements necessary to predict AS-level paths and is simple enough to run on standard client hardware. We validate the accuracy of the path predictor rst compared to classical path prediction algorithms, then compared to traceroute data taken from Planet Lab. The simulator predicts paths with similar sets of ASes and links nding 90% of the actual ASes seen in the traceroute data. The e ects of choosing paths utilizing the new path predictions is then investigated to nd that load balancing is adversely a ected. The entropy loss due to the new path selection method is also investigated, speci cally the entropy of the client from an adversary observing the exit/destination path. We nd that choosing paths with our new path selection algorithm results in minimal entropy loss. Overall, the results demonstrate that the new path simulator is a lightweight solution to defend against AS and IX-level compromise of anonymous communication paths on the Internet and should be considered for deployment to maintain the privacy guarantees of such systems.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2012-07-07T16:57:50Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 2 Juen_Joshua.pdf: 851189 bytes, checksum: f4b1fe29f1540b4a2874712b610b90d7 (MD5) Juen_Joshua.pdf: 851188 bytes, checksum: bd088489aae99082de661bed73b8346b (MD5)","Made available in DSpace on 2012-09-18T21:13:21Z (GMT). No. of bitstreams: 2 Juen_Joshua.pdf: 851188 bytes, checksum: bd088489aae99082de661bed73b8346b (MD5) license.txt: 4058 bytes, checksum: bed7a4ca4d8611af4837cf3ba7f586f2 (MD5)"]},{"key":"dc:title","label":"Title","values":["Protecting anonymity in the presence of autonomous system and internet exchange level adversaries"]}]}],"canonical_facts":{"dc:contributor":["Borisov, Nikita"],"dc:creator":["Juen, Joshua"],"dc:date":["2012-09-18T21:13:21Z","2012-08"],"dc:description":["This thesis analyzes the threat of autonomous system (AS) and Internet exchange (IX) level adversaries on Tor, currently the most widely deployed and used anonymity overlay network. Of particular interest is the possibility of a single AS or IX point observing both the path from the client to the entry node and the path from the exit node to the nal destination. Experimental results indicate that a non-trivial number of circuits are vulnerable to such compromise. A novel AS-level path prediction algorithm is developed in order to allow the client to choose paths without vulnerabilities. The path prediction algorithm sacri ces some accuracy in the top path prediction in order to decrease the hardware requirements necessary to predict AS-level paths and is simple enough to run on standard client hardware. We validate the accuracy of the path predictor rst compared to classical path prediction algorithms, then compared to traceroute data taken from Planet Lab. The simulator predicts paths with similar sets of ASes and links nding 90% of the actual ASes seen in the traceroute data. The e ects of choosing paths utilizing the new path predictions is then investigated to nd that load balancing is adversely a ected. The entropy loss due to the new path selection method is also investigated, speci cally the entropy of the client from an adversary observing the exit/destination path. We nd that choosing paths with our new path selection algorithm results in minimal entropy loss. Overall, the results demonstrate that the new path simulator is a lightweight solution to defend against AS and IX-level compromise of anonymous communication paths on the Internet and should be considered for deployment to maintain the privacy guarantees of such systems.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2012-07-07T16:57:50Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 2 Juen_Joshua.pdf: 851189 bytes, checksum: f4b1fe29f1540b4a2874712b610b90d7 (MD5) Juen_Joshua.pdf: 851188 bytes, checksum: bd088489aae99082de661bed73b8346b (MD5)","Made available in DSpace on 2012-09-18T21:13:21Z (GMT). No. of bitstreams: 2 Juen_Joshua.pdf: 851188 bytes, checksum: bd088489aae99082de661bed73b8346b (MD5) license.txt: 4058 bytes, checksum: bed7a4ca4d8611af4837cf3ba7f586f2 (MD5)"],"dc:identifier":["http://hdl.handle.net/2142/34363"],"dc:language":["en"],"dc:rights":["Copyright 2012 Joshua Paul Joseph Juen"],"dc:subject":["Anonymity","Autonomous Overlay Networks","Privacy","Tor","Networking"],"dc:title":["Protecting anonymity in the presence of autonomous system and internet exchange level adversaries"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:31Z"}