[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] Re: How is this attack causing 900 Mbps download and 100 Mbps upload?



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 2026-09-10 18:55, Red Oaive via tor-relays wrote:
> I was, unfortunately, more interested in defending than analysis and I
> no longer have any attacked nodes.

Defending is exactly why I'm trying to analyze it.

What bothers me the most about the attack is the fact that CPU load is
independent of the amount of bandwidth being used. Even when limiting
the bandwidth rate so the relay is only pushing through a trickle, the
CPU load remains pegged at 100%.

> I only have six relays I run or manage, and two of them had been
> attacked simultaneously.  Including one I would consider a point of
> interest, which is why I am concerned these are not just DoS attacks
> but aimed at deanonymizing some traffic.

I have 61, but still only saw two of them being attacked. One was an
exit and one was not. Both were serving directory requests. Why do you
consider one particular one of yours a point of interest?

I agree that they aren't just DDoS attacks for the sake of harming the
network. There would be easier ways to do that. It's certainly either an
attempt at deanonymizing some client or server (or even just confirming
or disproving use of a certain guard) or it's part of proof-of-concept
research to do just that.

> I find the attacks stop within an hour of activating DirCache 0.
> Likely as the attacker realizes their attack is spinning its wheels
> and no longer achieving asymmetric replies.

It might just be coincidence that it stops, because the relay is still
suffering extreme asymmetric load (now in the opposite direction) and
_something_ causes the CPU load to remain at 100%. It can't just be
denied directory fetches, since a relay refusing a directory request is
not using a lot of CPU to do so (unlike, say, diffing, compressing, and
sending the directory request itself over and over).

> There is also a forum discussion on these attacks.  I highly recommend
> developer input into this as automated defenses from outside tor is
> problematic at best.

I agree and I'm a bit surprised that there hasn't been any announcement
about it or even acknowledgement. Even "we're aware of it and and trying
to figure out solutions" would be helpful. Although I also acknowledge
that they are busy and quickly developing an ad-hoc mitigation probably
isn't going to be one of their priorities. Arti is.

Regarding the forum post, I disagree with the suggestion that offending
relays should be blacklisted. I _highly_ doubt the relays themselves are
aware of the attack. Unlike the recent circuit-building attack that came
from Contabo and Hetzner IPs, this one is routed through the Tor network
itself. The only solution is to limit the amount of resources that a
directory fetch can take up. If a relay is overloaded, I think it would
be much better for the network if directory fetches slowed down than if
everything slowed down to a crawl.

Regards,
forest
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCaqTomAAKCRAw+TRLM+X4
xpYkAPkBf4BSgNx0K4D17seG3KUm0s6bpfUyJQEpEfXrgx3CfwD+IHHz3n36mGfH
NvuXPrv0noX3BeXDCDcWQ7QgajsMCQE=
=ArQp
-----END PGP SIGNATURE-----
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx