Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Tor – Weighing the Benefits and Risks
News & Analysis

Tor – Weighing the Benefits and Risks

ISBuzz TeamBy ISBuzz TeamFebruary 11, 2015Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
tor
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Security teams and IT managers face a continuous battle to stay aware of everything users are accessing from their corporate environments. Anonymous web browsing technology such as The Onion Router (Tor) makes this problem even more difficult. While non-work-related internet browsing (like checking social media, looking at pictures of cats, etc.) is harmless the majority of time, there are some cases in which businesses could become unknowing participants in criminal activity, that is, when users hide that activity via the Tor network or the Dark Net.

Tor is a piece of software that is designed to permit a user to anonymously browse the internet via a volunteer network of more than 5000 relays. There are indeed legitimate uses for this technology, such as providing internet access in repressively regulated countries. However, it’s often linked with illicit activity like child pornography, identity theft, money laundering, etc. Most administrators will want to ban their users from using the Tor network from within their organisations due to its association with disreputable activity.

Free eBook: Modern Retail Security Risk – Get your copy now.

Users browsing the Tor network from a corporate environment can unwittingly expose the company to hosting malicious/illegal content, ransomware infection, or unknowingly participating in other malicious activity. If users are browsing with Tor and they are looking at child pornography, then the company can be liable. Wired recently reported that 80% of visits to Tor hidden services relate to child pornography.  Additionally, the notorious Silk Road online black market used mostly for buying and selling illegal drugs famously operated under the cover of Tor and was later taken down by the FBI.

Since the point of origin is almost impossible to determine conventionally, many bad actors leverage the Tor network to hide the location of Command & Control (CnC) servers, machines taking ransomware payments, etc. This makes identifying them and their malware that much harder.

And Tor is not only an open network that enables anonymity; it also provides anonymity for servers that can only be accessed through the Tor network, which are called hidden services.

Some websites allow accessing Tor hidden services through the Internet without being inside the Tor network. In that case, security managers will need to take corrective action and stay up to date with rules and techniques to help them detect when a system is accessing one of these services. Various families of malware are starting to use Tor to hide traffic and occlude the point of origin for communication with C&C servers. Adding correlation rules that group different IDS signatures to detect when a system is trying to resolve a malicious onion domain will be critical to prevent this malware from entering your network.

Since Tor itself is intended to be undetectable for the most part, deciding on policies or rules in advance in terms of business use is essential. It is also critical to train staff about the risks it poses. However, if you decide you want to actually block Tor, it is possible: https://www.torproject.org/docs/faq-abuse.html.en#Bans and/or https://www.torproject.org/projects/tordnsel.html.en.

Tor can be a useful tool in some cases; however, it does frequently get a bad reputation due to the associated nefarious activity. It is important to weigh these points when considering whether or not to allow the use of Tor on your network. Unless legitimate uses are known to your organisation, it would be best to limit its use because the reality is that more and more bad actors are using Tor and the related I2P for attacks, either to obfuscate the CnC communication and/or the makeup of their federated crime networks. So, when it comes down to it, a proper use case for business may need to be put forward, the and risks vs. benefits of using Tor must be assessed carefully.

By Garrett Gross, Senior Technical Manager, AlienVault

About AlienVault

AlienVaultAlienVault is the leading provider of Unified Security Management and crowd-sourced threat intelligence. Its products are designed and priced to ensure that mid-market organizations can effectively defend themselves against today’s advanced threats. By building the best open source security tools into one Unified Security Management platform, and then powering the platform with up-to-the-minute threat intelligence from AlienVault Labs and its Open Threat Exchange—the world’s largest crowd-sourced collaborative threat exchange—AlienVault provides its customers with a unified, simple and affordable solution for threat detection and compliance management.

While the perfect threat deflector shield has yet to be invented, AlienVault is able to provide its customers with an out-of-this-world threat detection product that ensures even the smallest ‘planets’ in the galaxy can fend off attackers.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}