FINDING · DETECTION

Randomization-based obfuscation systems (obfs2/3, obfs4, ScrambleSuit, Dust) resist blacklist DPI but fail entirely under protocol-whitelist filtering, as explicitly demonstrated during the Iranian elections where censors permitted only known-good protocols. Pure randomization provides no signal of being a permitted protocol, making it trivially blockable under any whitelist regime.

From 2015-dyer-marionetteMarionette: A Programmable Network-Traffic Obfuscation System · §1, §2 · 2015 · USENIX Security Symposium

Implications

Tags

censors
ir
techniques
dpirandom-payload-detect
defenses
randomizationobfs4scramblesuit

Extracted by claude-sonnet-4-6 — review before relying.