-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 On 2026-09-10 18:55, Red Oaive via tor-relays wrote:
I was, unfortunately, more interested in defending than analysis and I no longer have any attacked nodes.
Defending is exactly why I'm trying to analyze it. What bothers me the most about the attack is the fact that CPU load is independent of the amount of bandwidth being used. Even when limiting the bandwidth rate so the relay is only pushing through a trickle, the CPU load remains pegged at 100%.
I only have six relays I run or manage, and two of them had been attacked simultaneously. Including one I would consider a point of interest, which is why I am concerned these are not just DoS attacks but aimed at deanonymizing some traffic.
I have 61, but still only saw two of them being attacked. One was an exit and one was not. Both were serving directory requests. Why do you consider one particular one of yours a point of interest? I agree that they aren't just DDoS attacks for the sake of harming the network. There would be easier ways to do that. It's certainly either an attempt at deanonymizing some client or server (or even just confirming or disproving use of a certain guard) or it's part of proof-of-concept research to do just that.
I find the attacks stop within an hour of activating DirCache 0. Likely as the attacker realizes their attack is spinning its wheels and no longer achieving asymmetric replies.
It might just be coincidence that it stops, because the relay is still suffering extreme asymmetric load (now in the opposite direction) and _something_ causes the CPU load to remain at 100%. It can't just be denied directory fetches, since a relay refusing a directory request is not using a lot of CPU to do so (unlike, say, diffing, compressing, and sending the directory request itself over and over).
There is also a forum discussion on these attacks. I highly recommend developer input into this as automated defenses from outside tor is problematic at best.
I agree and I'm a bit surprised that there hasn't been any announcement about it or even acknowledgement. Even "we're aware of it and and trying to figure out solutions" would be helpful. Although I also acknowledge that they are busy and quickly developing an ad-hoc mitigation probably isn't going to be one of their priorities. Arti is. Regarding the forum post, I disagree with the suggestion that offending relays should be blacklisted. I _highly_ doubt the relays themselves are aware of the attack. Unlike the recent circuit-building attack that came from Contabo and Hetzner IPs, this one is routed through the Tor network itself. The only solution is to limit the amount of resources that a directory fetch can take up. If a relay is overloaded, I think it would be much better for the network if directory fetches slowed down than if everything slowed down to a crawl. Regards, forest -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCaqTomAAKCRAw+TRLM+X4 xpYkAPkBf4BSgNx0K4D17seG3KUm0s6bpfUyJQEpEfXrgx3CfwD+IHHz3n36mGfH NvuXPrv0noX3BeXDCDcWQ7QgajsMCQE= =ArQp -----END PGP SIGNATURE-----