Security and Forensic Analysis of Dark Web Exploration via the Tor Network
Abstract
The paper discuss about the utility of anonymity provided by Tor network and evaluate its security and forensic limitations. Whonix was used to create a controlled experimental environment to simulate the use of the dark web anonymously. The study combines network traffic analysis, browser fingerprinting, open-source intelligence (OSINT) and metadata forensics in order to evaluate possible anonymity leaks. The results indicate that, although Tor is an effective mechanism to hide user identity at the network-level, there are still considerable vulnerabilities on the application and behavioral levels. The browsing fingerprinting, metadata leakage and operational security (OPSEC) failures can be the causes of user deanonymization. The practice of real-life scenarios and trial and error reveals that anonymity is not merely dependent on the Tor infrastructure but also appropriate user practices. The paper ends up concluding that, to attain a strong anonymity, a layered security strategy that uses technical tools and trained user practices is needed. The paper represents a practical and experimental analysis of Tor anonymity that entailed a mixture of both network and behavioral and forensic analysis.