FINDING · EVALUATION

Pryde generates more than 6,000 successful and unique evasion attacks against 4 popular stateful firewalls, which is 2–3 orders of magnitude higher than censorship circumvention algorithms (e.g., Geneva) and black-box fuzzing. The gap arises because circumvention tools only uncover shallow evasion sequences and cannot systematically explore the full attack-state space.

From 2024-moon-prydePryde: A Modular Generalizable Workflow for Uncovering Evasion Attacks Against Stateful Firewall Deployments · §1 Introduction, Finding 1 · 2024 · Symposium on Security \& Privacy

Implications

Tags

censors
generic
techniques
middlebox-interferencedpi
defenses
geneva

Extracted by claude-sonnet-4-6 — review before relying.