FINDING · DETECTION

Obfsproxy3 and obfsproxy4 are reliably detected by an entropy-distribution test (KS test, block size k=8) applied to the first 2,048 bytes of the first client-to-server packet, combined with a minimum payload-length check of 149 bytes. On three university campus datasets totaling over 14 million TCP flows, the test achieves TPR=1.0 with FPR ranging from 0.24% to 0.33%. Omitting the length check raises the SSL/TLS false-positive rate to approximately 23%.

From 2015-wang-seeingSeeing through Network-Protocol Obfuscation · §5.1, Table 5 · 2015 · Computer and Communications Security

Implications

Tags

censors
generic
techniques
dpirandom-payload-detecttraffic-shape
defenses
obfs4randomization

Extracted by claude-sonnet-4-6 — review before relying.