FINDING · DETECTION

FreeWave's modem generates audio whose packet-length distribution has dramatically lower variance than human speech, even when transmitted through Skype's variable-bit-rate encoder; Figure 9 shows that English and Portuguese speech samples produce high-variance packet-length sequences while modem audio produces a narrow, nearly constant distribution, providing a reliable passive classifier for modem-over-VoIP traffic. This content mismatch persists even with perfect emulation of the VoIP protocol framing.

From 2013-geddes-coverCover Your ACKs: Pitfalls of Covert Channel Censorship Circumvention · §6, Figure 9 · 2013 · Computer and Communications Security

Implications

Tags

censors
generic
techniques
traffic-shapedpi
defenses
mimicry

Extracted by claude-sonnet-4-6 — review before relying.