Home / Current Issue / Paper 1716951
De-Anonymizing Entities on Onion Sites Operating in The TOR Network
Subject area: Science,Engineering and Technology · Area of research: De-Anonymizing
DOI: 10.64388/IREV9I10-1716951
Abstract
The Tor network provides anonymous communication through layered encryption and distributed relay routing. While essential for privacy protection, Tor has also been leveraged for illicit marketplaces and cybercrime coordination. Conventional surveillance approaches are ineffective due to onion routing and hidden service isolation. This paper proposes a comprehensive deanonymization framework integrating traffic metadata analysis, supervised and unsupervised machine learning, deep flow correlation techniques, and structured OpenSource Intelligence (OSINT) enrichment. The system bridges probabilistic traffic inference with contextual entity mapping using weighted evidence models. A detailed methodology covering controlled traffic acquisition, feature engineering, adversarial modeling, validation protocols, and OSINT scoring is presented. The framework emphasizes ethical compliance, reproducibility, and investigator usability. Results demonstrate that combining ML-based traffic inference with OSINT enrichment significantly improves actionable intelligence while maintaining analytical rigor.
Keywords
Tor, Deanonymization, Hidden Services, Website Fingerprinting, Flow Correlation, OSINT, Machine Learning, Cybersecurity
References
[1] B. Wu, D. M. Divakaran, L. Csikor, and M. Gurusamy, “RECTor: Robust and efficient correlation attack on Tor,” 2025. [Online]. Available: arXiv:2512.00436. :contentReference[oaicite:0]index=0
[2] Y. Cui et al., “A comprehensive survey of website fingerprinting attacks and defenses in Tor: Advances and open challenges,” 2025. [Online]. Available: arXiv:2510.11804. :contentReference[oaicite:1]index=1
[3] D. Liu and Y. Park, “Anonymous traffic detection based on feature engineering and reinforcement learning,” Sensors, vol. 24, no. 7, 2024. :contentReference[oaicite:2]index=2
[4] “A blind flow fingerprinting and correlation method against disturbed anonymous traffic based on pattern reconstruction,” Computer Networks, vol. 254, 2024. :contentReference[oaicite:3]index=3
[5] J. Holland, Tor Traffic Analysis: Data-driven Attacks and Defenses, Ph.D. dissertation, Univ. of Minnesota, 2024. :contentReference[oaicite:4]index=4
[6] “A comprehensive analysis of website fingerprinting defenses on Tor,” Computers & Security, vol. 136, 2024. :contentRefer-ence[oaicite:5]index=5
[7] “Effective website fingerprinting attack based on the first packet direction only,” Computer Networks, vol. 231, 2023. :contentReference[oaicite:6]index=6
[8] J. Saleem, M. R. Islam, and Z. Islam, “Darknet traffic analysis: A systematic literature review,” IEEE Access, 2024. :contentReference[oaicite:7]index=7
[9] H.-W. Huang, C.-H. Shih, C.-Y. Li, and H.-Y. Teng, “A blockchain-based framework for OSINT evidence collection and identification,” Future Internet, vol. 17, no. 12, 2025. :contentReference[oaicite:8]index=8
[10] “1 TRACE: Open-source intelligence platform for digital investigations,” 2024–2025. [Online]. Available: Wikipedia. :contentReference[oaicite:9]index=9
How to cite this paper
@article{1716951,
author = {Falguni Sultane, Mrunali Waghdhare, Anushka Jirge, Prof. Sudhakar Yerme},
title = {De-Anonymizing Entities on Onion Sites Operating in The TOR Network},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {9},
number = {10},
pages = {3591-3597},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1716951.pdf},
abstract = {The Tor network provides anonymous communication through layered encryption and distributed relay routing. While essential for privacy protection, Tor has also been leveraged for illicit marketplaces and cybercrime coordination. Conventional surveillance approaches are ineffective due to onion routing and hidden service isolation. This paper proposes a comprehensive deanonymization framework integrating traffic metadata analysis, supervised and unsupervised machine learning, deep flow correlation techniques, and structured OpenSource Intelligence (OSINT) enrichment. The system bridges probabilistic traffic inference with contextual entity mapping using weighted evidence models. A detailed methodology covering controlled traffic acquisition, feature engineering, adversarial modeling, validation protocols, and OSINT scoring is presented. The framework emphasizes ethical compliance, reproducibility, and investigator usability. Results demonstrate that combining ML-based traffic inference with OSINT enrichment significantly improves actionable intelligence while maintaining analytical rigor.},
keywords = {Tor, Deanonymization, Hidden Services, Website Fingerprinting, Flow Correlation, OSINT, Machine Learning, Cybersecurity},
month = {April},
doi = {https://doi.org/10.64388/IREV9I10-1716951}
}