FINDING · DETECTION

Frolov et al. (2020) found that over 94% of Internet servers respond with data to at least one popular protocol probe, making probe-resistant proxies that remain entirely silent statistically anomalous. Censors can further fingerprint silent proxies by their unique timeout or data-limit behaviors before connection close (e.g., Lampshade closes immediately after 256 bytes of unrecognized data, or waits exactly 90 seconds before timing out).

From 2020-frolov-httptHTTPT: A Probe-Resistant Proxy · §2 Background · 2020 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
active-probingtraffic-shape
defenses
obfs4scramblesuitshadowsocks

Extracted by claude-sonnet-4-6 — review before relying.