How reliable are VPN, proxy, hosting and Tor classifications?¶
title: "How reliable are VPN, proxy, hosting and Tor classifications?" card_id: "IP-073" status: "complete" source_document: "https://docs.google.com/document/d/1ArkxzV7_hjnL9zF8WagKtXYfoyLMFKB59LVtm66Y654/edit?usp=drivesdk"
How reliable are VPN, proxy, hosting and Tor classifications?¶
An IP lookup labels an address as a VPN, proxy, hosting service or Tor exit node.
How much confidence should you place in that label?
Classification services build their results from different sources.
They may use public routing and registration data, known provider address ranges, lists of Tor relays, network measurements, observed behaviour or information supplied by commercial partners.
No single source is complete.
Some classifications are relatively straightforward.
An address registered to a well-known cloud provider is likely to belong to hosted infrastructure.
But that still doesn't show how the individual address was being used. It could host a website, VPN, proxy, ordinary business application or compromised server.
VPN and proxy classifications can be more difficult.
Providers add and remove servers. Residential proxy services may use addresses that look like ordinary household connections.
A privately operated VPN or proxy may never appear on a commercial list.
An address can also change purpose without changing provider.
Tor publishes information about relays, but the relevant question is whether the address was operating as an exit at the time of the event.
A current Tor classification can't simply be applied to activity that occurred months earlier.
Different lookup services may disagree because they use different evidence and update their databases at different times.
A false positive may label ordinary infrastructure as a proxy or VPN. A false negative may leave an active intermediary classified as residential or business broadband.
Classification therefore helps form a working assessment.
It may explain why an address doesn't lead directly to an ordinary subscriber or suggest which records and attribution routes are realistic.
It doesn't prove that the particular activity passed through the classified service.
The result should be considered alongside the provider, timestamp, routing information and other records from the event.
“Classified as VPN” is an intelligence assessment about infrastructure.
It isn't the same as proving that a particular user deliberately used a VPN during the activity being investigated.