FINDING · DETECTION

SSH transfers utilized only 15% of available bandwidth versus 85–89% for HTTP/HTTPS. When SSH was obfuscated by XORing payloads with a constant key (hiding the plaintext handshake), throughput dropped to near-zero during all trials. Applying the same obfuscation to HTTP transfers produced the same near-zero result, supporting the hypothesis that Iran whitelists known-approved protocols rather than blacklisting specific ones, which would preemptively block any unrecognized or randomized transport including Tor's obfsproxy.

From 2013-aryan-internetInternet Censorship in Iran: A First Look · §4.4 · 2013 · Free and Open Communications on the Internet

Implications

Tags

censors
ir
techniques
traffic-shapethrottlingrandom-payload-detect

Extracted by claude-sonnet-4-6 — review before relying.