FINDING · DETECTION

Shadowsocks traffic appears as ordinary TCP with no payload keywords or obvious protocol markers because the entire payload is encrypted; firewalls cannot distinguish it from generic TLS without behavioral flow analysis. This makes signature- and keyword-based detection ineffective against it.

From 2017-deng-randomThe Random Forest based Detection of Shadowsock's Traffic · §III.A · 2017 · Intelligent Human-Machine Systems and Cybernetics

Implications

Tags

censors
cn
techniques
dpikeyword-filtering
defenses
shadowsocksrandomization

Extracted by claude-sonnet-4-6 — review before relying.