FINDING · EVALUATION

Three open-source DPI tools (Zeek, libprotoident, nDPI) fail to identify 93–100% of UPGen flows across all tools. libprotoident misidentified 7% of UPGen flows as RTMP; nDPI and Zeek produced zero false labels. On a real-world MAWI/WIDE backbone capture, Zeek failed to recognize 90% of flows and nDPI failed on 67%, confirming that unidentified-protocol traffic is common in the wild; allowlisting without significant collateral damage (≥4%) is infeasible.

From 2025-wails-censorshipCensorship Evasion with Unidentified Protocol Generation · §4.4, Table 5, Table 6 · 2025 · USENIX Security Symposium

Implications

Tags

censors
generic
techniques
dpi
defenses
meta-resistance

Extracted by claude-sonnet-4-6 — review before relying.