FINDING · DETECTION

Geneva packet-manipulation probing traffic exhibits distinctive features — corrupt data-offset fields, smaller packet sizes, overlapping TCP segments, TTL variance, and non-zero SYN packets — that allow simple ML classifiers (Decision Trees, Random Forests, Logistic Regression, SVM) to detect it with AUC > 0.99. A subsequent TRW-based IP-level detector can then block the source IP with high confidence after inspecting only 2 Geneva probing flows.

From 2023-amich-deresistorDeResistor: Toward Detection-Resistant Probing for Evasion of Internet Censorship · §4.1–§4.2 · 2023 · USENIX Security Symposium

Implications

Tags

censors
cninkz
techniques
ml-classifierdpitraffic-shape
defenses
geneva

Extracted by claude-sonnet-4-6 — review before relying.