Network Fingerprinting Using Machine Learning for Anonymous Networking Detection in Cryptocurrency
Abstract
Cryptocurrency such as Bitcoin supports anonymous routing (Tor and I2P) because of the application requirements of anonymity and censorship resistance. In permissionless and open networking for cryptocurrency, an adversary can spoof to pretend to use Tor or I2P for anonymity and privacy protection, while in reality it is not using anonymous routing and forwarding its networking directly to the destination peer to reduce the networking overheads. Using profile detection to detect anonymous routing and false claims based on the deterministic features are vulnerable to spoofing, especially in the permissionless cryptocurrency bypassing registration control. We therefore design and build network fingerprinting using the networking behaviors to detect and classify the networking types. We build a network sensor to collect data on an active Bitcoin node connected to the Mainnet and apply supervised machine learning to classify if a peer node is using IP (not anonymous), Tor, or I2P. Our results show that our scheme is effective in accurately detecting the networking types and identifying spoofing attempts through supervised machine learning. Our machine learning model accurately classifies the networking types and detects fake claims of Tor usage with 90% accuracy and false claims of I2P with 87% accuracy in permisionless Bitcoin.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.