NetShuffle targets edge networks — small autonomous systems and entities that obtain
IP address blocks from upstream providers — as a new class of support base for
circumvention infrastructure. This class has received scant attention from prior
work, which has focused on cloud providers and volunteer desktop machines. Edge
networks represent a large pool of diverse IP space that is harder to block via ASN
blackholing compared to a small number of major cloud providers.
From 2024-kon-netshuffle — NetShuffle: Circumventing Censorship with Shuffle Proxies at the Edge
· §1, §2
· 2024
· Symposium on Security \& Privacy
Implications
Diversify proxy infrastructure across small edge ASNs rather than concentrating it on major cloud providers; edge-ASN IP space is harder to blackhole without significant collateral damage to legitimate traffic.
Identify and engage edge-network operators (campus networks, regional ISPs, small enterprise networks) as a proxy support base distinct from cloud VMs and volunteer desktops.