FINDING · DEFENSE

Format-Transforming Encryption (FTE) fails under proxy-induced ciphertext modification — a single character change causes decryption failure — while Marionette's probabilistic context-free grammar (CFG) templates tolerate header rewriting, connection multiplexing, and content alteration by intermediate proxies. Validated across 10,000 streams through Squid 3.4.9, achieving 5.8 Mbps downstream and 0.41 Mbps upstream goodput.

From 2015-dyer-marionetteMarionette: A Programmable Network-Traffic Obfuscation System · §7.3 · 2015 · USENIX Security Symposium

Implications

Tags

techniques
dpimiddlebox-interference
defenses
marionetteformat-transform

Extracted by claude-sonnet-4-6 — review before relying.