FINDING · DEFENSE

NetShuffle decouples regular proxy services (e.g., HTTPS proxies, Tor bridges) from their network addresses via continuous in-network change using programmable switches at edge networks. Because the network location of a proxy is in constant flux, blocking by IP or address enumeration becomes structurally ineffective: the proxy service itself is unchanged but its visible address rotates continuously.

From 2024-kon-netshuffleNetShuffle: Circumventing Censorship with Shuffle Proxies at the Edge · §1, §3 · 2024 · Symposium on Security \& Privacy

Implications

Tags

censors
generic
techniques
ip-blocking
defenses
bridges

Extracted by claude-sonnet-4-6 — review before relying.