FINDING · DETECTION

OpenVPN's application-layer P_ACK packets — uniform in size and concentrated only in the handshake phase — provide a timing and count fingerprint detectable via threshold comparison over 10-packet bins. Tunnel-based obfuscation wrappers (Stunnel, SSH, obfs2/3, Shadowsocks) that do not add random padding preserve the 1:1 packet correspondence with the underlying OpenVPN stream, leaving 16 of 20 tested tunnel-based obfuscated configurations vulnerable to ACK fingerprinting.

From 2022-xue-openvpnOpenVPN is Open to VPN Fingerprinting · §6.2, §9.1 · 2022 · USENIX Security Symposium

Implications

Tags

censors
generic
techniques
dpitraffic-shape
defenses
obfs4randomizationtunnelingshadowsocks

Extracted by claude-sonnet-4-6 — review before relying.