Evaluating Practical Enumeration and Blocking Attacks on the Snowflake Circumvention System
Linden Chen, Ryan Sangha, Cecylia Bocovich, Ram Sundara Raman
Abstract
Proxy-based Internet censorship circumvention tools like Snowflake rely on large, dynamic pools of third-party proxies to resist IP-based blocking. We focus on two assumptions underpinning the security of Snowflake: that adversaries cannot easily enumerate proxy IPs, and that blocking those proxies would incur unacceptable collateral damage. In this paper, we test these assumptions by studying practical enumeration and blocking attacks against Snowflake conducted by malicious clients. We combine bounded, ethical real-world measurements with large-scale simulation to evaluate both present-day enumeration and blocking risk and broader attacker capabilities. Over 48 days of real-world measurements from May--June 2025, our attack enumerated over 21,000 unique proxy IP addresses belonging to almost 1,000 autonomous systems. Despite this high number, we find that proxy churn limits the overall effectiveness of enumeration over time, and reduces the impact on clients of individual proxy addresses being blocked. However, at the network level, blocking the top 1% of observed autonomous systems blocks more than 30% of observed Snowflakes while affecting 0% of Tranco Top 100 domains and 2.5% of Top 1M domains. We discover that the broker's load-aware matching reveals stable, high-capacity proxies to attackers early, especially during periods of elevated demand such as the censorship even in Iran of June 2025, subsequently exposing the networks that contribute disproportionately to system connectivity. In simulation, increasing attacker scale sharply improves both enumeration and blocking success, while higher proxy churn significantly reduces blocking effectiveness. We conclude by discussing and evaluating practical mitigations, some of which have been integrated into Snowflake.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on21
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- The use of TLS in Censorship CircumventionSergey Frolov, Eric WustrowNDSS 2019 · 97 citations
- SoK: Towards Grounding Censorship Circumvention in EmpiricismMichael Carl Tschantz, Sadia Afroz, anonymous, Vern PaxsonS&P 2016 · 89 citations
- Augur: Internet-Wide Detection of Connectivity DisruptionsPaul Pearce, Roya Ensafi, Frank Li, Nick Feamster et al.S&P 2017 · 84 citations
- Censored Planet: An Internet-wide, Longitudinal Censorship ObservatoryRam Sundara Raman, Prerana Shenoy, Katharina Kohls, Roya EnsafiCCS 2020 · 68 citations
Related papers
- Snowflake, a censorship circumvention system using temporary WebRTC proxiesCecylia Bocovich, Arlo Breault, David Fifield, Serene et al.USENIX Security 2024 · 18 citations
- SpotProxy: Rediscovering the Cloud for Censorship CircumventionPatrick Tser Jern Kon, Sina Kamali, Jinyu Pei, Diogo Barradas et al.USENIX Security 2024 · 7 citations
- IRBlock: A Large-Scale Measurement Study of the Great Firewall of IranJonas Tai, Karthik Nishanth Sengottuvelavan, Peter Whiting, Nguyen Phong HoangUSENIX Security 2025
- Detecting Probe-resistant ProxiesSergey Frolov, Jack Wampler, Eric WustrowNDSS 2020
- Fingerprinting Obfuscated Proxy Traffic with Encapsulated TLS HandshakesDiwen Xue, Michalis Kallitsis, Amir Houmansadr, Roya EnsafiUSENIX Security 2024 · 24 citations
