FINDING · DETECTION

A semantics-based attack that flags HTTP flows carrying structurally invalid PDF documents as Stegotorus produces false-positive rates as high as 43% across three campus datasets (10,847 PDF flows examined), because malformed, partial, and non-standard PDFs are common in real network traffic. By contrast, active HTTP-response fingerprinting of a suspected Stegotorus server yields only 0.03% false positives (3 matching servers out of 9,320 Alexa-top-10K servers), but requires active probing and is detectable by the proxy operator.

From 2015-wang-seeingSeeing through Network-Protocol Obfuscation · §4.1–§4.2, Tables 3–4 · 2015 · Computer and Communications Security

Implications

Tags

censors
generic
techniques
dpiactive-probing
defenses
mimicry

Extracted by claude-sonnet-4-6 — review before relying.