Traffic Correlation Attack
Definition
A deanonymisation technique that compares timing patterns and traffic volume at the entry point of a Tor circuit and at the destination, allowing an observer with visibility at both ends to probabilistically identify the user. Also called an end-to-end timing attack. It does not require breaking Tor's encryption.
- Also called
- End-to-end timing attack
- Target
- Tor circuit entry point and destination traffic
- Method
- Compares timing and volume patterns
- Encryption required to break
- None
Common questions
Why doesn't a traffic correlation attack need to break Tor's encryption?+
It works purely on metadata, the timing and size of packets, rather than their content, so it identifies users by matching traffic patterns rather than decrypting anything carried inside the circuit.
Who is realistically capable of carrying out this attack?+
It requires simultaneous visibility at both the entry guard and the destination or exit point, a capability generally limited to actors who can monitor large portions of network traffic, such as major network operators or state-level agencies.
Related terms
- Blockchain Analysis
- The forensic examination of a cryptocurrency's public transaction ledger to trace the flow of funds between addresses, cluster addresses controlled by the...
- Exit Node
- The third relay in a Tor circuit, which forwards decrypted traffic to the public internet destination. The destination server sees the exit...
- I2P (Invisible Internet Project)
- A peer-to-peer anonymity network that routes traffic through a distributed mesh of volunteer nodes using unidirectional tunnels. Unlike Tor, I2P is primarily...
- Onion Routing
- A technique in which a message is encrypted in multiple layers, one per relay node, so that each relay decrypts only its...
- Onion Service (Hidden Service)
- A server reachable through Tor using a .onion address derived from its public key. The server's real IP address is never exposed...