FINDING · DEFENSE
Because Rook runs the actual game client and server rather than mimicking them, active anti-mimicry probes receive identical responses to a normal game instance. Systems based on protocol mimicry are vulnerable to probes that expose non-conforming behavior, but Rook eliminates this attack surface entirely.
From 2015-vines-rook — Rook: Using Video Games as a Low-Bandwidth Censorship Resistant Communication Platform · §4.2 Anti-Mimicry · 2015 · Workshop on Privacy in the Electronic Society
Implications
- Circumvention designs should run the real cover application rather than mimicking it — running the actual binary eliminates the probe-response divergence that defeats mimicry-based transports (cf. 'Parrot is Dead').
- For any game-based covert channel, using a real licensed server/client binary (or a protocol-complete open-source reimplementation) is a prerequisite for active-probing resistance.
Tags
Extracted by claude-sonnet-4-6 — review before relying.