FINDING · DETECTION

The GFW was observed detecting Shadowsocks servers by sending follow-up active probes after an initial Shadowsocks-sized client message, including permuted replays of the client's message and random-data probes of various sizes up to and exceeding Shadowsocks' unique 50-byte data limit. This defeats shadowsocks-libev's replay cache because the GFW permutes the replayed bytes rather than resending them verbatim.

From 2020-frolov-httptHTTPT: A Probe-Resistant Proxy · §2 Background · 2020 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
active-probingrandom-payload-detect
defenses
shadowsocks

Extracted by claude-sonnet-4-6 — review before relying.