Search
Search Results
Found one item.
1 - 1 of 1 items
The suppression of illegal activities of Internet users is one of the urgent problems of information
security in the Russian Federation. The suppression of the activities of persons committing
illegal actions using digital technologies, in particular, using the Tor anonymous network, is one
of the tasks of federal law enforcement agencies that ensure information security. The difficulty of
detecting and identifying the use of the Tor software package in data transmission networks is due
to a number of measures taken by its developers aimed at masking the data flow of the complex,
including the use of modern algorithms for encryption of data packets. The aim of the work is to
create and describe a set of attributes for establishing an https-connection by the Tor softwarepackage in the context of using TLS data encryption using the version 1.3 protocol. The tasks of
the work are the preparation and analysis of traffic materials of the Tor software package, as well
as the creation, based on the data obtained, of a set of signs of establishing a connection between
the client and the server of the anonymous network. In the course of analyzing the data flow of the
anonymous network, the stage of establishing a connection between the client and the input server
of the chain of nodes of the Tor network, the so-called "TLS handshake", was investigated. It
should be noted that this work complements previous studies on the analysis of TLS encryption in
terms of the TLS v1.3 encryption protocol used since 2018, describing its features as part of the
mechanism for implementing anonymization by the Tor software package. The authors propose to
use the size of the "TLS handshake" packets as the main features that carry identifying information
about the establishment of an anonymous connection between the client and the Tor network node.
The reported study was funded by Russian Ministry of Science (information security), project
number 23/2020.