FINDING · DEFENSE

Active-probing censors who discover a shadow domain can be defeated by adding a CDN rule that only fetches from the blocked back-end when a secret custom request header is present; without it the CDN returns an innocuous response. Layering domain fronting over domain shadowing (DfDs) further hides the shadow domain by routing the initial request through an allowed front domain with the Host header set to the shadow domain, so the censor never sees the shadow domain in the SNI or DNS query even during active inspection.

From 2021-wei-domainDomain Shadowing: Leveraging Content Delivery Networks for Robust Blocking-Resistant Communications · §6.1.2, §3.4 · 2021 · USENIX Security Symposium

Implications

Tags

censors
generic
techniques
active-probingsni-blocking
defenses
domain-frontingtunneling

Extracted by claude-sonnet-4-6 — review before relying.