Detection and Analysis of Tor Onion Services

Keywords: Tor, Darknet, onion services, analysis


Tor onion services can be accessed and hosted anonymously on the Tor network.
We analyze the protocols, software types, popularity and uptime of
these services by collecting a large amount of .onion addresses. Websites are
crawled and clustered based on their respective language. In order to also
determine the amount of unique websites a de-duplication approach is implemented.
To achieve this, we introduce a modular system for the real-time
detection and analysis of onion services. The overall data reveals
that a large amount of permanent services provide no actual content for Tor
users. A significant part consists instead of bots, services offered via multiple
domains, or duplicated websites for phishing attacks. The total amount of
onion services is thus significantly smaller than current statistics suggest


Author Biographies

Martin Steinebach, Fraunhofer SIT, Germany

Martin Steinebach is the manager of the Media Security and IT Forensics division at Fraunhofer SIT. From 2003 to 2007 he was the manager of the Media Security in IT division at Fraunhofer IPSI. He studied computer science at the Technical University of Darmstadt and finished his diploma thesis on copyright protection for digital audio in 1999. In 2003 he received his PhD at the Technical University of Darmstadt for this work on digital audio watermarking. In 2016 he became honorary professor at the TU Darmstadt. He gives lectures on Multimedia Security as well as Civil Security. He is Principle Investigator at ATHENE and represents IT Forensics and AI security. Before he was Principle Investigator at CASED with the topics Multimedia Security and IT Forensics. In 2012 his work on robust image hashing for detection of child pornography reached the second rank “Deutscher IT Sicherheitspreis”, an award funded by Host Görtz.

Marcel Schäfer, Fraunhofer USA CESE

Marcel Schäfer serves as Senior Research Scientist for the Fraunhofer USA Center for Experimental Engineering CESE in Maryland since 2019. From 2009 to 2018 he was with Fraunhofer Institute for Secure Information Technologies SIT in Germany. With a Master’s degree in mathematics from the University of Wuppertal, Germany and a PhD in computer science from the Technical University of Darmstadt, Germany, he consults and teaches for topics on dark web, privacy networks and anonymous communication, and also serves as a subject matter expert for privacy, e.g. GDPR and data anonymization. As PI, Co-PI and researcher Dr. Schäfer has lead and worked in various projects that discover new challenges and opportunities broadly spread over the fields of cybersecurity and software engineering in both the public and private sector.

Katharina Brandl, Fraunhofer SIT, Germany

Katharina Brandl studied computer science in Marburg and finished her master degree in 2012. During her studies she was part of the programming languages research group of Prof. Ostermann where she also wrote her master thesis about a type system for parametric tree grammars. Since 2017 she is part of the PANDA project at the Fraunhofer SIT. The PANDA project is an interdisciplinary project researching the darknet and there she is responsible for the computer science part of the project.


ARES 2019 workshops