Hey guys, I'm almost ready to publish my HS but I first want to stress test my onion balance setup and in general the whole onion layer to see how it could react against ddos attacks, to see if my logs setup is comprehensive and well organized even under intense ddos attacks, etc.
I already tested the web application defenses, what i want to focus on is tor-specific attacks like introduction cells attacks and any other attack that can be disruptive at the tor level, but all I was able to find is some old research and some blog post, nothing particularly valuable.
I tried to fuck around with stem but it's very limited in "bad actions" you can do. Writing my own "bad client" would require a lot of time, I'm not THAT familiar with tor.
For HS admins, how do you usually proceed for this kind of tests?
Kind of gray area but I'll approve this I see this as a valuable discussion.