FINDING · DEFENSE

Conjure registration is unidirectional: the client embeds a steganographic ciphertext tag in a complete HTTPS request payload encrypted under a Diffie-Hellman shared secret, and the station passively observes it without sending any reply or spoofing packets. This design makes registration flows indistinguishable from normal HTTPS traffic and enables 25% more viable registration decoys than TapDance by removing the requirement to exclude decoys with short TCP windows or connection timeouts.

From 2019-frolov-conjureConjure: Summoning Proxies from Unused Address Space · §4.1 · 2019 · Computer and Communications Security

Implications

Tags

censors
generic
techniques
dpiactive-probing
defenses
conjuredecoy-routingtunneling

Extracted by claude-sonnet-4-6 — review before relying.