FINDING · EVALUATION

A two-phase passive-filter-plus-active-probing framework deployed at a 1-million-user ISP identified 85.90% of vanilla OpenVPN flows (1,718/2,000) and 72.67% of obfuscated flows (1,468/2,020), with an upper-bound false positive rate of 0.0039% across over 10 million flows — three orders of magnitude lower than prior ML-based approaches (1.4–5.5%). The system processed 15 TB and 2 billion flows per day on a single commodity server.

From 2022-xue-openvpnOpenVPN is Open to VPN Fingerprinting · §9, Table 3 · 2022 · USENIX Security Symposium

Implications

Tags

censors
generic
techniques
dpiactive-probingtraffic-shape
defenses
obfs4randomization

Extracted by claude-sonnet-4-6 — review before relying.