FINDING · DEFENSE

DNS-sly requires out-of-band distribution of a 2.3 MB compressed bootstrap package (user profile map) before covert communication begins. The authors explicitly reject automated in-band bootstrapping to preserve deniability, accepting a hard scalability constraint as the cost; the particular censored environment tested did not interfere with DNS traffic at all, enabling successful censored-site retrieval at the same throughput rates as uncensored tests.

From 2016-akbar-dns-slyDNS-sly: Avoiding Censorship through Network Complexity · §3.2, §4.2 · 2016 · Free and Open Communications on the Internet

Implications

Tags

censors
generic
techniques
active-probingdpi
defenses
dns-tunneling

Extracted by claude-sonnet-4-6 — review before relying.