Publications
2027
- On the Effectiveness of NetFlow-Based Deanonymization of Tor Onion ServicesJinseo Lee, Jongkook Han, Yixin Sun, and Min Suk KangIn Proceedings of the 48th IEEE Symposium on Security and Privacy, Montreal, Canada, 2027
In the context of Tor, deanonymization attacks via traffic correlation have long been studied for both clients and onion services. Complementing prior investigations that utilize fine-grained flow metadata such as packet sizes and timings, we study a relatively less explored yet easier-to-obtain adversarial capability: deanonymization using only coarse NetFlow-style telemetry, such as one-minute, 1-out-of-1,000 sampled packet counts. We first revisit active NetFlow-based traffic analysis attacks against Tor onion services and show, through large-scale experiments with live Tor data, that coarse telemetry is sufficient to deanonymize a targeted onion service when the adversary can induce discernible traffic patterns through controlled downloads. We then introduce a stronger active attack based on controlled introduction requests, which removes application-specific assumptions and gives adversaries more flexibility while achieving comparable success rates. Finally, we present a passive deanonymization attack that sends zero traffic to target onion services. The attack exploits Tor’s puzzle-based DoS defense as a side channel: public puzzle difficulty reveals service-load changes that can be semantically matched against NetFlow traces. Our findings show that coarse network telemetry poses a practical deanonymization threat to onion services today and call for proactive mitigations, such as IP rotation and a redesign of globally visible defense signals that may leak service-load information.
@inproceedings{lee27effectiveness, author = {Lee, Jinseo and Han, Jongkook and Sun, Yixin and Kang, Min Suk}, title = {On the Effectiveness of NetFlow-Based Deanonymization of Tor Onion Services}, booktitle = {Proceedings of the 48th IEEE Symposium on Security and Privacy}, series = {IEEE S&P '27}, year = {2027}, location = {Montreal, Canada}, publisher = {IEEE}, address = {New York, NY, USA}, }
2025
- Onions Got Puzzled: On the Challenges of Mitigating Denial-of-Service Problems in Tor Onion ServicesJinseo Lee, Hobin Kim, and Min Suk KangIn Proceedings of the 34th USENIX Security Symposium, Seattle, WA, USA, 2025
Honorable Mention: Selected among 25 recognized papers out of 407 (6%).
Denial-of-service (DoS) attacks present significant challenges for Tor onion services, where strict anonymity requirements render conventional mitigation strategies inapplicable. In response, the Tor community has recently revived the client puzzle idea in an official update to address real-world DoS attacks, leading to its adoption by several major onion services. In this paper, we uncover a critical vulnerability in the current puzzle system in Tor through a novel family of attacks, dubbed ONIONFLATION. The proposed attacks artificially inflate the required puzzle difficulty for all clients without causing noticeable congestion at the targeted service, rendering any existing onion service largely unusable at an attack cost of a couple of dollars per hour. Our ethical evaluation on the live Tor network demonstrates the impact of these attacks, which we have reported to the Tor Project and received acknowledgment. Our analysis reveals an undesirable trade-off in the client puzzle mechanism, which is the root cause of the discovered vulnerability, that forces the Tor onion system to choose between inflation resistance and congestion resistance, but not both. We offer practical guidance for Tor onion services aimed at balancing the mitigation of these attacks.
@inproceedings{lee25onions, author = {Lee, Jinseo and Kim, Hobin and Kang, Min Suk}, title = {Onions Got Puzzled: On the Challenges of Mitigating {Denial-of-Service} Problems in Tor Onion Services}, booktitle = {Proceedings of the 34th USENIX Security Symposium}, series = {USENIX Security '25}, year = {2025}, location = {Seattle, WA, USA}, numpages = {19}, publisher = {USENIX Association}, address = {Berkeley, CA, USA}, }
2024
- Measuring DNS-over-HTTPS Downgrades: Prevalence, Techniques, and Bypass StrategiesJinseo Lee, David Mohaisen, and Min Suk KangProc. ACM Netw., Nov 2024
DNS-over-HTTPS (DoH) is a privacy-enhancing protocol that encrypts plaintext query data in DNS resolution. However, DoH often faces accessibility challenges due to phenomena known as DoH downgrades, where DoH queries are reverted to plaintext DNS queries. Unlike downgrades in other security protocols, which are undoubtedly malicious, the act of downgrading DoH queries can be both desirable and undesirable depending on the context; e.g., enterprise networks are officially advised to avoid or downgrade DoH for security reasons. Recent research has drawn attention to the deeper examination of the phenomena of DoH downgrades, focusing on the prevalence, techniques, and potential bypass strategies. However, existing studies on DoH downgrades have several limitations, notably that they severely overestimate the severity of DoH downgrades across the globe as they lack any distinction between desirable and undesirable downgrades of DoH. In this work, we conduct a large-scale measurement study to provide a more accurate depiction of the DoH downgrade landscape. By minimizing the influence of desirable downgrades of DoH in our measurement probes, we show a skewed long-tail distribution of DoH downgrades across the globe. Our stateful probing techniques also reveal hidden DoH filtering mechanisms that were previously undetected. Furthermore, we design near perfect bypass strategies against existing DoH downgrades. Our study expands our limited understanding of DoH downgrades, offering a more accurate, fine-grained, and comprehensive view of the phenomena.
@article{lee24measuring, author = {Lee, Jinseo and Mohaisen, David and Kang, Min Suk}, title = {Measuring DNS-over-HTTPS Downgrades: Prevalence, Techniques, and Bypass Strategies}, year = {2024}, issue_date = {December 2024}, publisher = {Association for Computing Machinery}, address = {New York, NY, USA}, volume = {2}, number = {CoNEXT4}, url = {https://doi.org/10.1145/3696385}, doi = {10.1145/3696385}, journal = {Proc. ACM Netw.}, month = nov, articleno = {28}, numpages = {22}, keywords = {bypass, dns privacy, dns-over-https, downgrade, measurement}, }