Conjure: Summoning Proxies from Unused Address Space
Sergey Frolov, Jack Wampler, Sze Chuen Tan, J. Alex Halderman, Nikita Borisov, Eric Wustrow
Abstract
Refraction Networking (formerly known as "Decoy Routing") has emerged as a promising next-generation approach for circumventing Internet censorship. Rather than trying to hide individual circumvention proxy servers from censors, proxy functionality is implemented in the core of the network, at cooperating ISPs in friendly countries. Any connection that traverses these ISPs could be a conduit for the free flow of information, so censors cannot easily block access without also blocking many legitimate sites. While one Refraction scheme, TapDance, has recently been deployed at ISP-scale, it suffers from several problems: a limited number of "decoy" sites in realistic deployments, high technical complexity, and undesirable tradeoffs between performance and observability by the censor. These challenges may impede broader deployment and ultimately allow censors to block such techniques. We present Conjure, an improved Refraction Networking approach that overcomes these limitations by leveraging unused address space at deploying ISPs. Instead of using real websites as the decoy destinations for proxy connections, our scheme connects to IP addresses where no web server exists leveraging proxy functionality from the core of the network. These phantom hosts are difficult for a censor to distinguish from real ones, but can be used by clients as proxies. We define the Conjure protocol, analyze its security, and evaluate a prototype using an ISP testbed. Our results suggest that Conjure can be harder to block than TapDance, is simpler to maintain and deploy, and offers substantially better network performance. CCS CONCEPTS • Networks → Network security; • Social and professional topics → Censorship.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 24a315e3-188e-48b7-8d44-389a2c7cf6abCited by top-tier papers10
- Poking a Hole in the Wall: Efficient Censorship-Resistant Internet Communications by Parasitizing on WebRTCDiogo Barradas, Nuno Santos, Luís E. T. Rodrigues, Vítor NunesCCS 2020 · 41 citations
- Snowflake, a censorship circumvention system using temporary WebRTC proxiesCecylia Bocovich, Arlo Breault, David Fifield, Serene et al.USENIX Security 2024 · 18 citations
- Retina: analyzing 100GbE traffic on commodity hardwareGerry Wan, Fengchen Gong, Tom Barbette, Zakir DurumericSIGCOMM 2022 · 14 citations
- Bridging Barriers: A Survey of Challenges and Priorities in the Censorship Circumvention LandscapeDiwen Xue, Anna Ablove, Reethika Ramesh, Grace Kwak Danciu et al.USENIX Security 2024 · 7 citations
- SpotProxy: Rediscovering the Cloud for Censorship CircumventionPatrick Tser Jern Kon, Sina Kamali, Jinyu Pei, Diogo Barradas et al.USENIX Security 2024 · 7 citations
Builds on5
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 632 citations
- The use of TLS in Censorship CircumventionSergey Frolov, Eric WustrowNDSS 2019 · 97 citations
- The Waterfall of Liberty: Decoy Routing Circumvention that Resists Routing AttacksMilad Nasr, Hadi Zolfaghari, Amir HoumansadrCCS 2017 · 43 citations
- Slitheen: Perfectly Imitated Decoy Routing through Traffic ReplacementCecylia Bocovich, Ian GoldbergCCS 2016 · 40 citations
- GAME OF DECOYS: Optimal Decoy Routing Through Game TheoryMilad Nasr, Amir HoumansadrCCS 2016 · 25 citations
Related papers
- NetShuffle: Circumventing Censorship with Shuffle Proxies at the EdgePatrick Tser Jern Kon, Aniket Gattani, Dhiraj Saharia, Tianyu Cao et al.S&P 2024 · 6 citations
- Practical Censorship Evasion Leveraging Content Delivery NetworksHadi Zolfaghari, Amir HoumansadrCCS 2016 · 44 citations
- Censorship Evasion with Unidentified Protocol GenerationRyan Wails, Rob Jansen, Aaron Johnson, Micah SherrUSENIX Security 2025
- GET /out: Automated Discovery of Application-Layer Censorship Evasion StrategiesMichael Harrity, Kevin Bock, Frederick Sell, Dave LevinUSENIX Security 2022
- The Discriminative Power of Cross-layer RTTs in Fingerprinting Proxy TrafficDiwen Xue, Robert Stanley, Piyush Kumar, Roya EnsafiNDSS 2025
