FINDING · DETECTION

obfs4 and obfs⋆ produce characteristic wire patterns—bursts of roughly MTU-sized payloads followed by a randomly-sized chaff packet—that CNN classifiers detect purely from packet-size sequences without payload inspection. A trivial per-bridge entropy-biasing re-encoding (obfs⋆) completely defeats the hand-tuned decision tree (0% precision, 0% recall) but does not reduce CNN detectability, because the CNN generalizes across size-distribution variants.

From 2024-wails-preciselyOn Precisely Detecting Censorship Circumvention in Real-World Networks · §V-E, §IV-D-3, Figure 4 · 2024 · Network and Distributed System Security

Implications

Tags

censors
generic
techniques
traffic-shapeml-classifierrandom-payload-detect
defenses
obfs4randomization

Extracted by claude-sonnet-4-6 — review before relying.