FINDING · DETECTION
SkypeMorph and StegoTorus-Embed fail 5 of 9 standard Skype identification tests (Table I), including the TCP control channel (T9), SoM packet headers (T3), and periodic message exchanges (T6/T7). All failures are detectable by a local (LO) passive censor at line speed without requiring ISP-scale statistical analysis.
From 2013-houmansadr-parrot — The Parrot is Dead: Observing Unobservable Network Communications · §VII-A, Table I · 2013 · Symposium on Security \& Privacy
Implications
- Protocol mimicry must replicate all side protocols and control channels, not just the primary data stream — omitting Skype's TCP control channel is a trivial passive giveaway detectable by a Wi-Fi router.
- Threat-model against the weakest plausible adversary (local passive observer) before worrying about ISP-scale classifiers; a transport that fails a local censor provides no real protection.
Tags
Extracted by claude-sonnet-4-6 — review before relying.