FINDING · EVALUATION
Game-specific trigram analysis of mutable fields distinguishes high-bandwidth Rook (1-in-2 substitution rate) in server-side packet counts, showing clearly reduced distinct-trigram counts versus baseline. Standard Rook (1-in-10) produces only a few outliers and is not reliably distinguishable; any detector would face a high false-negative or false-positive rate against normal-rate Rook.
From 2015-vines-rook — Rook: Using Video Games as a Low-Bandwidth Censorship Resistant Communication Platform · §4.3 Game-Specific n-gram Analysis · 2015 · Workshop on Privacy in the Electronic Society
Implications
- A game-specific n-gram detector is feasible but requires the censor to build a per-game packet parser and perform full-capture stateful analysis — this raises the attack cost significantly above stateless DPI.
- Dynamic self-adjusting symbol tables (monitoring how substitutions shift statistical distributions and reweighting accordingly) are the recommended mitigation if trigram-based detection becomes a practical threat.
Tags
Extracted by claude-sonnet-4-6 — review before relying.