USENIX Security2022Top-tier venue
GET /out: Automated Discovery of Application-Layer Censorship Evasion Strategies
Michael Harrity, Kevin Bock, Frederick Sell, Dave Levin
Abstract
The censorship arms race has recently gone through a transformation, thanks to recent efforts showing that new ways to evade censorship can be discovered in an automated fashion. However, all of these prior automated efforts operate by manipulating TCP/IP headers; while impressive, deploying these have proven challenging, as header modifications often require greater privileges than are available to censorship circumvention apps. In that line of work, the application layer has gone largely unexplored. This is not without reason: the space of application messages is much larger and far less structured than TCP/IP headers. In this paper, we present the first techniques to automate the discovery of new censorship evasion techniques purely in the application layer. We present a general solution and apply it specifically to HTTP and DNS censorship in China, India, and Kazakhstan. Our automated techniques discovered a total of 77 unique evasion strategies for HTTP and 9 for DNS, all of which require only application-layer modifications, making them easier to incorporate into apps and deploy. We analyze these strategies and shed new light into the inner workings of the censors. We find that the success of application-layer strategies can depend heavily on the type and version of the destination server. Surprisingly, a large class of our evasion strategies exploit instances in which censors are more RFCcompliant than popular application servers. We have made our code publicly available.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4b2f8f3c-1e2b-4664-9b6f-d81e8b9eaa0aCited by top-tier papers10
- Measuring and Evading Turkmenistan's Internet Censorship: A Case Study in Large-Scale Measurements of a Low-Penetration CountrySadia Nourin, Van Hong Tran, Xi Jiang, Kevin Bock et al.WWW 2023 · 25 citations
- GFWeb: Measuring the Great Firewall's Web Censorship at ScaleNguyen Phong Hoang, Jakub Dalek, Masashi Crete-Nishihata, Nicolas Christin et al.USENIX Security 2024 · 22 citations
- In Search of netUnicorn: A Data-Collection Platform to Develop Generalizable ML Models for Network Security ProblemsRoman Beltiukov, Wenbo Guo, Arpit Gupta, Walter WillingerCCS 2023 · 10 citations
- Cooperative Dynamics of Censorship, Misinformation, and Influence Operations: Insights from the Global South and U.SZaid Hakami, Yuzhou Feng, Bogdan CarbunarCSCW 2025 · 2 citations
- Fingerprinting Deep Packet Inspection Devices by their AmbiguitiesDiwen Xue, Armin Huremagic, Wayne Wang, Ram Sundara Raman et al.CCS 2025
Builds on9
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- Measuring HTTPS Adoption on the WebAdrienne Porter Felt, Richard Barnes, April King, Chris Palmer et al.USENIX Security 2017 · 177 citations
- Quack: Scalable Remote Measurement of Application-Layer CensorshipBenjamin VanderSloot, Allison McDonald, Will Scott, J. Alex Halderman et al.USENIX Security 2018 · 66 citations
- Geneva: Evolving Censorship Evasion StrategiesKevin Bock, George Hughey, Xiao Qiang, Dave LevinCCS 2019 · 60 citations
- Weaponizing Middleboxes for TCP Reflected AmplificationKevin Bock, Abdulrahman Alaraj, Yair Fax, Kyle Hurley et al.USENIX Security 2021 · 49 citations
Related papers
- Come as You Are: Helping Unmodified Clients Bypass Censorship with Server-side EvasionKevin Bock, George Hughey, Louis-Henri Merino, Tania Arya et al.SIGCOMM 2020 · 17 citations
- Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-LayerNiklas Niere, Felix Lange, Robert Merget, Juraj SomorovskyS&P 2025
- CircumVolve: Automated Discovery of Censorship Evasion Strategies Using Large Language ModelsAli Zohaib, Jackson Sippe, Jade Sheffey, Mingshi Wu et al.CCS 2026
- How the Great Firewall of China Detects and Blocks Fully Encrypted TrafficMingshi Wu, Jackson Sippe, Danesh Sivakumar, Jack Burg et al.USENIX Security 2023
- DeResistor: Toward Detection-Resistant Probing for Evasion of Internet CensorshipAbderrahmen Amich, Birhanu Eshete, Vinod Yegneswaran, Nguyen Phong HoangUSENIX Security 2023
