FINDING · DEFENSE

Marionette is the first programmable obfuscation system to simultaneously satisfy all five threat-model dimensions evaluated in Figure 2: resistance to blacklist DPI, whitelist DPI, statistical-test DPI, protocol-enforcing proxy traversal, and multi-layer traffic control, while sustaining throughput above 1 Mbps (up to 6.7 Mbps). Every prior system (obfs4, ScrambleSuit, SkypeMorph, StegoTorus, FTE, JumpBox, etc.) fails at least one dimension, most commonly stateful proxy traversal or statistical-feature control.

From 2015-dyer-marionetteMarionette: A Programmable Network-Traffic Obfuscation System · §2, Figure 2 · 2015 · USENIX Security Symposium

Implications

Tags

techniques
dpitraffic-shapemiddlebox-interferenceactive-probing
defenses
marionettemeta-resistanceformat-transformrandomization

Extracted by claude-sonnet-4-6 — review before relying.