FINDING · DEFENSE

Protozoa creates a ≈1.4 Mbps covert channel over WebRTC by replacing encoded video frames with covert payload while preserving SRTP packet size and timing properties, making Protozoa flows 'hardly distinguishable from unmodified WebRTC streams using existing ML-based traffic classifiers.' Since all unencrypted packet fields remain intact, DPI cannot detect the tunnel either.

From 2020-barradas-towardsTowards a Scalable Censorship-Resistant Overlay Network based on WebRTC Covert Channels · §2 · 2020 · Distributed Infrastructure for Common Good

Implications

Tags

censors
generic
techniques
dpiml-classifiertraffic-shape
defenses
webrtc-pluggabletunneling

Extracted by claude-sonnet-4-6 — review before relying.