pith. sign in

arxiv: 1507.05819 · v3 · pith:3WN7ER37new · submitted 2015-07-21 · 💻 cs.CY · cs.LG· cs.NI

On Identifying Anomalies in Tor Usage with Applications in Detecting Internet Censorship

classification 💻 cs.CY cs.LGcs.NI
keywords eventsanomalouscensorshipdailyusageanomaliesapproachdemonstrate
0
0 comments X
read the original abstract

We develop a means to detect ongoing per-country anomalies in the daily usage metrics of the Tor anonymous communication network, and demonstrate the applicability of this technique to identifying likely periods of internet censorship and related events. The presented approach identifies contiguous anomalous periods, rather than daily spikes or drops, and allows anomalies to be ranked according to deviation from expected behaviour. The developed method is implemented as a running tool, with outputs published daily by mailing list. This list highlights per-country anomalous Tor usage, and produces a daily ranking of countries according to the level of detected anomalous behaviour. This list has been active since August 2016, and is in use by a number of individuals, academics, and NGOs as an early warning system for potential censorship events. We focus on Tor, however the presented approach is more generally applicable to usage data of other services, both individually and in combination. We demonstrate that combining multiple data sources allows more specific identification of likely Tor blocking events. We demonstrate the our approach in comparison to existing anomaly detection tools, and against both known historical internet censorship events and synthetic datasets. Finally, we detail a number of significant recent anomalous events and behaviours identified by our tool.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. ICLab: A Global, Longitudinal Internet Censorship Measurement Platform

    cs.CR 2019-07 conditional novelty 7.0

    ICLab is a new internet censorship measurement platform using commercial VPNs for global longitudinal detection of DNS manipulation, TCP injection, and block pages, with observations of 3,602 blocked URLs across 60 co...