Onions Got Puzzled: On the Challenges of Mitigating Denial-of-Service Problems in Tor Onion Services
Jinseo Lee (Kais)
34th USENIX Security Symposium (USENIX Security '25) · Day 2 · Network Security 2: Routing and DoS
Overview
This talk, presented by Jinseo Lee from KAIST, delves into the persistent and evolving challenge of Denial-of-Service (DoS) attacks against Tor Onion Services. While Tor is renowned for providing anonymity to both clients and servers, this very design makes traditional DoS mitigation techniques largely ineffective. The presentation highlights a critical vulnerability in Tor's recently adopted Proof of Work (PoW) puzzle defense, introducing a novel attack called Onion Inflation. This attack, which was developed in collaboration with Coven Kim and advisor Muk, demonstrates how a low-volume attacker can trick an onion service into drastically escalating the computational burden on legitimate users, effectively degrading service and causing widespread timeouts.

Key moments
- 0:00 Introduction to Tor Onion Services and DoS vulnerability
- 2:00 Why common DoS mitigations fail for Tor
- 2:40 Tor's adoption of Proof-of-Work Puzzles
- 4:00 Introducing the Onion Inflation Attack
- 5:00 How Onion Inflation exploits the difficulty update algorithm
- 7:00 Limitations of current slow and global difficulty updates
- 9:30 Proposed solution: Tunable difficulty update algorithm
Onions Got Puzzled: On the Challenges of Mitigating Denial-of-Service Problems in Tor Onion Services
Speakers: Jinseo Lee, Researcher, KAIST
Conference: USENIX Security
YouTube: https://www.youtube.com/watch?v=1OJLZgxvTTI
Overview
This talk, presented by Jinseo Lee from KAIST, delves into the persistent and evolving challenge of Denial-of-Service (DoS) attacks against Tor Onion Services. While Tor is renowned for providing anonymity to both clients and servers, this very design makes traditional DoS mitigation techniques largely ineffective. The presentation highlights a critical vulnerability in Tor's recently adopted Proof of Work (PoW) puzzle defense, introducing a novel attack called Onion Inflation. This attack, which was developed in collaboration with Coven Kim and advisor Muk, demonstrates how a low-volume attacker can trick an onion service into drastically escalating the computational burden on legitimate users, effectively degrading service and causing widespread timeouts.
The significance of this research cannot be overstated. Tor's onion services are vital for privacy-conscious communication, protecting dissidents, journalists, and everyday users from surveillance and censorship. A sustained DoS vulnerability directly undermines the reliability and usability of these services, pushing users towards less secure alternatives. The talk not only exposes a critical flaw in Tor's current DoS mitigation strategy, which was adopted in response to a network-wide attack campaign, but also proposes a robust solution involving a tunable security parameter, offering a path forward for enhancing the resilience of the Tor network.
Background
▶ Watch: Introduction to Tor Onion Services and DoS vulnerability (0:00)
Tor, or "The Onion Router," is a free and open-source software that enables anonymous communication. It directs internet traffic through a worldwide volunteer overlay network, consisting of thousands of relays, to conceal a user's location and usage from anyone conducting network surveillance or traffic analysis. Tor Onion Services, formerly known as hidden services, extend this anonymity to servers, allowing them to operate without revealing their IP addresses. Communication with an onion service involves a multi-layered relay system: a client initiates a request to the onion service via introduction points, and if the service accepts, it establishes a connection through a designated rendezvous point, forming an end-to-end circuit with the client. This intricate setup preserves the anonymity of both the client and the onion service.
However, this very design, while excellent for anonymity, inherently exposes onion services to Denial-of-Service (DoS) attacks. An attacker can send numerous requests to the introduction points, which are then forwarded to the onion service. Each such request compels the onion service to establish a new tool socket, a resource-intensive operation. If a sufficient volume of these requests arrives, the onion service can become overwhelmed, exhausting its resources and denying legitimate users access. This is not a theoretical concern; in 2023, the Tor Project officially acknowledged a network-wide DoS campaign that plagued onion services for a staggering seven months, severely impacting their availability and reliability.
The Tor community attempted to deploy common DoS mitigation strategies, but these efforts largely failed due to Tor's stringent anonymity requirements. For instance, rate limiting, which involves restricting clients sending excessive requests, is impractical when the client's identity (IP address) is unknown. Similarly, scrubbing (redirecting suspicious traffic to a powerful service) and over-provisioning (creating multiple duplicates of a service) are difficult to implement without compromising anonymity or incurring significant costs and infrastructure burdens that conflict with Tor's decentralized, volunteer-run nature.
Faced with these challenges, the Tor Project revisited an older but powerful idea: Proof of Work (PoW) puzzles. In 2023, PoW puzzles were officially adopted as the primary mitigation for DoS attacks against onion services. The mechanism is straightforward: if an onion service detects a DoS attack, it issues cryptographic puzzles to all incoming connection attempts. Clients (including attackers) must solve these puzzles to establish a tool socket. The computational effort required to solve these puzzles is intended to act as a deterrent, making it prohibitively expensive for attackers to flood the service with requests, thereby curbing incoming attack traffic and protecting the onion service. Initial tests showed that this PoW puzzle defense worked remarkably well against classic DoS attacks, appearing to be a robust solution.
Key Findings
▶ Watch: Tor's adoption of Proof-of-Work Puzzles (2:40)
Despite the initial success of PoW puzzles against classic DoS attacks, the research presented by Jinseo Lee unveils a critical vulnerability: the Onion Inflation Attack. This novel DoS attack effectively neutralizes the PoW puzzle defense by exploiting how onion services dynamically adjust puzzle difficulty. Instead of overwhelming the service with high-volume traffic, the Onion Inflation attacker sends a very small attack volume strategically, tricking the onion service into misinterpreting the network state.
The core finding is that the onion service is deceived into believing it is under a severe DoS attack, leading it to significantly inflate the puzzle difficulty. This "skyrocketed" difficulty then impacts everyone, including benign clients, who must now expend substantial computational resources and time to solve these extremely challenging puzzles. The practical consequence is a dramatic increase in client waiting times, with almost half of the legitimate clients experiencing timeouts (after 90 seconds) during the researchers' tests, effectively breaking the only available DoS mitigation at the time.
The root cause of the Onion Inflation Attack lies in two fundamental problems with the existing PoW puzzle's difficulty update algorithm:
- Symptom-Based Congestion Measurement: The algorithm is designed to detect different "symptoms" of congestion. As demonstrated by the "last request sending symptom" example, it inspects the queue only at specific points (e.g., the end of a measurement period). This limited, symptom-based approach makes it susceptible to manipulation by an attacker who can strategically trigger these symptoms without generating sustained high traffic.
- Limited Difficulty Update Mechanism:
- Extremely Slow Updates: The difficulty is updated only every 5 minutes. This slow update cycle is a structural limitation, as more frequent updates would impose a significant burden on the entire Tor network infrastructure, which is not designed for rapid, network-wide state changes.
- Global Feedback Only: The system allows only global feedback, meaning all clients are issued puzzles of the same difficulty. There is no mechanism for individual feedback or dynamic adjustment per client, again due to Tor's strong anonymity requirements which preclude tracking individual client behavior.
A crucial theoretical finding from this research is the discovery of a fundamental trade-off (D3): "No difficulty calculation algorithm can be simultaneously resistant to both congestion and inflation attacks." The current PoW puzzle's algorithm, designed primarily to combat classic congestion-based DoS, leans heavily towards "congestion resistance," making it inherently vulnerable to the "inflation" type of attack.
To address this, the researchers propose a novel mitigation strategy. Instead of focusing on symptom-based detection, they advocate for a holistic queue measurement approach that monitors the overall status of the queue throughout the entire measurement period. More importantly, they introduce a tunable security parameter that allows onion service operators to control the balance between resistance to congestion and resistance to inflation attacks. By carefully tuning this parameter, a "sweet spot" can be found that provides robust defense against both classic DoS and the Onion Inflation attack, with only moderate delays for legitimate clients.
Technical Deep Dive
▶ Watch: Introducing the Onion Inflation Attack (4:00)
The Proof of Work (PoW) puzzle defense, adopted by Tor in 2023, functions by requiring clients to perform a computational task before establishing a connection to an onion service. When an onion service experiences congestion or detects an attack, it issues a cryptographic puzzle. Successful completion of this puzzle is a prerequisite for creating a tool socket, which is necessary for communication. The difficulty of these puzzles is dynamically adjusted by an difficulty update algorithm within the onion service.
The core vulnerability exploited by the Onion Inflation Attack lies in this difficulty update algorithm. The current algorithm operates on a symptom-based congestion measurement model. It periodically (e.g., every 5 minutes) inspects certain indicators to infer congestion. A concrete example highlighted in the talk is the "last request sending symptom." At the end of each 5-minute measurement period, the algorithm checks if any requests are still remaining in the queue. If there are, it interprets this as a symptom of congestion and, consequently, increases the puzzle difficulty for the subsequent period.
The Onion Inflation Attack leverages this symptom-based detection with a strategy called End Rush. During a 5-minute measurement period, the attacker does not send a continuous flood of requests. Instead, they strategically send a few hundred requests only towards the very end of the 5-minute period. These requests arrive just as the measurement period is concluding, ensuring that some requests are still in the queue when the algorithm performs its check for the "last request sending symptom." This low-volume, precisely timed burst of traffic is enough to trigger the symptom, causing the victim onion service to erroneously conclude that it is under a significant DoS attack and thus inflate the puzzle difficulty. The talk mentions that three additional inflation strategies are detailed in their full paper, indicating the breadth of attack vectors against this symptom-based approach.
Beyond the specific vulnerability of symptom-based measurement, the researchers point to a more fundamental structural problem with Tor's difficulty update mechanism:
- Extremely Slow Update Frequency: The puzzle difficulty is updated only once every 5 minutes. This slow update cycle is not arbitrary; it's a necessity imposed by the very architecture of the Tor network. Propagating frequent difficulty updates across the decentralized, global Tor infrastructure would impose an unsustainable burden on the network, leading to performance degradation or even instability. This constraint prevents the system from reacting quickly to evolving attack conditions or rapidly de-escalating difficulty once an attack subsides.
- Global Feedback Limitation: The current system provides only global feedback, meaning all clients attempting to connect to a particular onion service are presented with puzzles of the same, uniform difficulty. There is no mechanism for individual feedback or personalized difficulty adjustments. This limitation stems directly from Tor's strong anonymity requirements, which prevent the onion service from distinguishing between benign and malicious clients or tracking individual client behavior without compromising privacy. This global difficulty setting means that if the difficulty is inflated due to an Onion Inflation attack, all legitimate clients suffer equally.
The researchers' key theoretical contribution is the identification of a fundamental trade-off (D3): "No difficulty calculation algorithm can be simultaneously resistant to both congestion and inflation attacks." This implies that an algorithm optimized to quickly respond to high-volume congestion (classic DoS) might be inherently susceptible to subtle inflation attacks, and vice-versa. The current PoW puzzle, designed primarily for classic DoS, leans towards congestion resistance, leaving it vulnerable to the Onion Inflation attack.
To mitigate this, the proposed solution moves away from symptom-based detection towards a more holistic queue measurement. Instead of just checking the queue at the end, the new approach would monitor the queue's status throughout the entire 5-minute period, providing a more comprehensive understanding of congestion. Crucially, they introduce a tunable security parameter. This parameter allows operators to control where the difficulty update algorithm sits on the spectrum of the D3 trade-off – balancing resistance to classic congestion attacks versus resistance to inflation attacks. By finding a "sweet spot" for this parameter, the mitigation can achieve robustness against both attack types.
Demo / Proof of Concept
▶ Watch: Limitations of current slow and global difficulty updates (7:00)
The talk presents compelling evidence of the Onion Inflation Attack's efficacy through a Proof of Concept (PoC) demonstration. The researchers conducted tests against the PoW puzzle defense currently deployed in Tor onion services. The primary metric used to evaluate performance was client waiting time, with longer waiting times indicating degraded service and poorer performance.
The results clearly illustrate the impact:
- Baseline & Classic DoS: In a baseline scenario (no attack) and under a classic, high-volume DoS attack, the PoW puzzle defense demonstrated its intended effectiveness. Client waiting times under classic DoS were similar to the baseline, confirming that the PoW mechanism successfully mitigates traditional congestion-based attacks.
- Onion Inflation Attack: When the Onion Inflation Attack was launched, the impact was dramatic. The average client waiting time significantly increased. More critically, almost half of the legitimate clients experienced timeouts after waiting for 90 seconds. This demonstrates that the Onion Inflation Attack effectively degrades the puzzle defense, making the onion service largely inaccessible to legitimate users.
The PoC effectively validates the theoretical claims, showing that a low-volume, strategically timed attack can indeed trick the onion service's difficulty update algorithm, leading to an inflated puzzle difficulty that severely impacts user experience and service availability. This practical demonstration underscores the urgency of addressing the identified vulnerabilities in Tor's current DoS mitigation.
Defensive Implications
▶ Watch: Proposed solution: Tunable difficulty update algorithm (9:30)
The findings presented in "Onions Got Puzzled" carry significant and immediate defensive implications for the Tor network and its onion service operators. The primary takeaway is that Tor's currently deployed Proof of Work (PoW) puzzle defense, while effective against classic, high-volume Denial-of-Service attacks, is fundamentally broken by the Onion Inflation Attack. This means that onion services remain vulnerable to a sophisticated, low-resource DoS vector that can severely degrade user experience and availability.
For Tor developers and onion service operators, the most critical defensive action is to replace or significantly modify the existing difficulty update algorithm. The current symptom-based congestion measurement, exemplified by the "last request sending symptom," must be abandoned in favor of a more robust approach. The researchers advocate for a holistic queue measurement strategy, which continuously monitors the overall status of the queue throughout the entire measurement period, rather than relying on snapshot observations. This would make it much harder for attackers to trigger false positives with strategically timed, low-volume bursts of traffic.
Furthermore, the proposed tunable security parameter is crucial for future implementations. Onion service operators should adopt an algorithm that incorporates such a parameter, allowing them to dynamically adjust the balance between resistance to congestion (classic DoS) and resistance to inflation (Onion Inflation). The research indicates that a "sweet spot" exists for this parameter, enabling robust defense against both types of attacks with only moderate delays for legitimate users. This flexibility is vital, as the threat landscape can change, and the ability to tune the defense mechanism without requiring a complete redesign offers significant operational advantages.
Beyond the immediate fix, the talk emphasizes the need for future work into alternative DoS defenses. While the proposed tunable algorithm offers a strong mitigation for the identified issues, the inherent challenges of DoS in an anonymous network like Tor mean that a multi-layered defense strategy is likely necessary. Researchers and developers should continue to explore ideas such as rate limiting or overflow reasoning that are compatible with Tor's strong anonymity requirements. This suggests an ongoing need for innovation to ensure the long-term resilience and reliability of Tor onion services against evolving DoS threats. Ultimately, the defensive implications call for a more sophisticated, adaptable, and holistic approach to DoS mitigation within the unique constraints of the Tor ecosystem.
Key Takeaways
- The Onion Inflation Attack effectively breaks Tor's current Proof of Work (PoW) puzzle defense, which was the only practically available DoS mitigation for onion services.
- The attack exploits the PoW puzzle's difficulty update algorithm, specifically its symptom-based congestion measurement (e.g., "last request sending symptom") and its limitations of slow, global feedback.
- Researchers discovered a fundamental trade-off (D3): no difficulty calculation algorithm can simultaneously resist both classic congestion attacks and inflation attacks. The current PoW leans towards congestion resistance, making it vulnerable to inflation.
- A new, tunable difficulty update algorithm is proposed, which incorporates a security parameter to balance resistance against both classic DoS attacks and the Onion Inflation attack.
- By adopting a more holistic queue measurement and tuning the security parameter to a "sweet spot," onion services can achieve robust defense against both attack types with moderate delays for benign clients.
- Future research is desired to design alternative DoS defenses, such as anonymity-preserving rate limiting or overflow reasoning, compatible with Tor's strong requirements.
About the Speaker(s)
The primary speaker for this presentation was Jinseo Lee, a researcher from KAIST (Korea Advanced Institute of Science and Technology). The work presented, titled "Onions Got Puzzled," was a joint effort with his colleague Coven Kim and their advisor Muk. While specific titles for Jinseo Lee and Coven Kim were not detailed beyond "researcher," their affiliation with KAIST suggests a strong academic background in computer science and security research. The collaboration highlights a team dedicated to addressing critical security challenges within complex systems like the Tor network.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Solid academic security research that identifies a genuine, previously undisclosed vulnerability in Tor's deployed PoW puzzle defense. The Onion Inflation attack is a real contribution — not a repackaged finding — and the theoretical proof of the congestion/inflation trade-off gives the work lasting value beyond the immediate fix.
Heather Calloway (CISO) — PASS
Technically credible academic research identifying a real flaw in Tor's PoW-based DoS mitigation and proposing a defensible fix. Outside my lane — no governance angle, no institutional accountability, no operator-level decision path for any organization I'd advise.
→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)
All talks from 34th USENIX Security Symposium (USENIX Security '25)