FINDING · DETECTION
The paper identifies that Shadowsocks can also serve as a transport layer for Tor and VPN connections, meaning a Shadowsocks flow detector functions as a first-stage classifier that unmasks compounded anonymity systems. The authors explicitly cite this as a motivation for detection.
From 2017-deng-random — The Random Forest based Detection of Shadowsock's Traffic · §II · 2017 · Intelligent Human-Machine Systems and Cybernetics
Implications
- Chaining Tor-over-Shadowsocks does not provide layered detection resistance if the outer Shadowsocks layer is already detectable by flow analysis — the outermost transport must independently evade classifiers.
- Circumvention stacks that combine protocols should ensure each layer is individually undetectable, not just the innermost.
Tags
Extracted by claude-sonnet-4-6 — review before relying.