FINDING · DETECTION

Format-transforming encryption (FTE) as deployed in the Tor Browser Bundle is detected by combining a URI Shannon-entropy threshold (≥5.5 bits) with an exact URI length check (239 bytes) on the first HTTP GET request. This embellished test produces only 264 false positives across approximately 10 million HTTP URIs in three campus datasets, while a length-only test causes roughly 15% false-positive rate over the same flows.

From 2015-wang-seeingSeeing through Network-Protocol Obfuscation · §5.2, Figure 6 · 2015 · Computer and Communications Security

Implications

Tags

censors
generic
techniques
dpitraffic-shape
defenses
format-transformpluggable-transport

Extracted by claude-sonnet-4-6 — review before relying.