- Solo lo 0.01% di Internet è accessibile attraverso il Dark Web
- Più di 2.5 milioni di utenti accedono quotidianamente a TOR
- Il 62% del Dark Web è utilizzato per servizi legali
- L’ammontare delle transazioni illecite nel 2023 ha superato i $14 miliardi
- Oltre 30.000 siti .onion attivi nel 2024
Principali Darknet
1. TOR (The Onion Router)
- Statistiche:
- 6000+ relay server
- 2000+ exit nodes
- Bandwidth totale: 500+ Gbps
- Accesso: torproject.org
- Caratteristiche:
- Routing a cipolla (3+ nodi)
- Hidden services (.onion)
- Bridge relay per paesi censurati
2. I2P (Invisible Internet Project)
- Statistiche:
- 55.000+ router attivi
- Crescita del 40% nel 2023
- Accesso: geti2p.net
- Caratteristiche:
- Garlic routing
- Eepsite (.i2p)
- Integrated applications
3. Freenet
- Statistiche:
- Storage distribuito
- 10.000+ nodi attivi
- Accesso: freenetproject.org
- Caratteristiche:
- Freesites
- Darknet mode
- Friend-to-friend networking
4. ZeroNet
- Statistiche:
- 100.000+ siti
- Decentralizzato
- Accesso: zeronet.io
- Caratteristiche:
- Bitcoin auth
- Torrent-like hosting
- No server centrale
Architettura e Funzionamento
TOR Network
[Client] → [Guard Node] → [Middle Node] → [Exit Node] → [Destination]
(encrypted) (encrypted) (decrypted)
I2P Network
[Client] → [Inbound Tunnels] → [Network Database] → [Outbound Tunnels] → [Destination]
(garlic encrypted) (distributed DHT) (garlic encrypted)
Use Cases Legittimi
- Giornalismo
- Protezione fonti
- Bypass censura
- Whistleblowing sicuro
- Privacy
- Comunicazioni private
- Protezione dati personali
- Bypass sorveglianza
- Ricerca
- OSINT
- Threat Intelligence
- Security Research
Strumenti Essenziali
1. Browser e Client
# TOR Browser hardening
about:config
network.security.ports.banned
network.proxy.socks_remote_dns
2. Security Tools
# Tails OS persistence
sudo tails-persistence-setup
# Whonix gateway config
sudo whonix_gateway
3. OPSEC Tools
# PGP key generation
gpg --full-generate-key --expert
# Verify onion addresses
curl --socks5-hostname localhost:9050
Threat Model
1. Attacchi Comuni
- Exit Node Monitoring
- Correlation Attacks
- Traffic Analysis
- De-anonymization
2. Contromisure
# Example: Check for exit node manipulation
def check_exit_node(onion_service):
with Controller.from_port() as controller:
circuit = controller.get_circuit(onion_service)
exit_node = circuit.path[-1]
return verify_node_fingerprint(exit_node)
Best Practices
1. OPSEC Guidelines
# Separate identities
torsocks-shell unique_identity_1
# Verify connection
curl --socks5-hostname localhost:9050 check.torproject.org
2. Sicurezza Operativa
- Compartimentazione
- Air-gapped systems
- Clean room environment
Monitoraggio e Detection
1. Network Traffic
# Example: Monitor for TOR traffic
def detect_tor_traffic(pcap_file):
packets = rdpcap(pcap_file)
tor_signatures = [
b'tor-browser',
b'tor-relay',
b'.onion'
]
for packet in packets:
if TCP in packet and packet[TCP].dport == 9050:
return True
for sig in tor_signatures:
if sig in raw(packet):
return True
return False
2. Endpoint Security
# Check for TOR processes
ps aux | grep tor
# Monitor network connections
netstat -tupln | grep ESTABLISHED
Risorse e Link Utili
1. Ricerca e Training
2. Security Tools
3. Research Papers
- “Tor: The Second-Generation Onion Router”
- “I2P: A Scalable Framework for Anonymous Communication”
- “Understanding Darknet Markets”
Monitoring & Intelligence
OSINT Tools
# Example: Onion crawler
from stem import Signal
from stem.control import Controller
def crawl_onion(onion_address):
with Controller.from_port() as controller:
controller.authenticate()
try:
response = requests.get(
onion_address,
proxies={'http': 'socks5h://127.0.0.1:9050',
'https': 'socks5h://127.0.0.1:9050'}
)
return response.text
except Exception as e:
print(f"Error: {e}")
controller.signal(Signal.NEWNYM)
Best Practices di Sicurezza
- Sistema Operativo
- Tails OS per massima sicurezza
- Whonix per isolamento
- Virtual Machine dedicata
- Comunicazione
- PGP per messaggi
- OTR per chat
- Secure Drop per file
- OPSEC
- VPN + Tor
- Different identities
- Air-gapped systems
Conclusioni
Il Dark Web rappresenta uno strumento potente che richiede:
- Comprensione tecnica approfondita
- Rigide pratiche di sicurezza
- Consapevolezza dei rischi
- Uso responsabile




