USENIX Security2024Top-tier venue
Fingerprinting Obfuscated Proxy Traffic with Encapsulated TLS Handshakes
Diwen Xue, Michalis Kallitsis, Amir Houmansadr, Roya Ensafi
Abstract
The global escalation of Internet censorship by nation-state actors has led to an ongoing arms race between censors and obfuscated circumvention proxies. Research over the past decade has extensively examined various fingerprinting attacks against individual proxy protocols and their respective countermeasures. In this paper, however, we demonstrate the feasibility of a protocol-agnostic approach to proxy detection, enabled by the shared characteristic of nested protocol stacks inherent to all forms of proxying and tunneling activities. We showcase the practicality of such an approach by identifying one specific fingerprint-encapsulated TLS handshakes-that results from nested protocol stacks, and building similaritybased classifiers to isolate this unique fingerprint within encrypted traffic streams. Assuming the role of a censor, we build a detection framework and deploy it within a mid-size ISP serving upwards of one million users. Our evaluation demonstrates that the traffic of obfuscated proxies, even with random padding and multiple layers of encapsulations, can be reliably detected with minimal collateral damage by fingerprinting encapsulated TLS handshakes. While stream multiplexing shows promise as a viable countermeasure, we caution that existing obfuscations based on multiplexing and random padding alone are inherently limited, due to their inability to reduce the size of traffic bursts or the number of round trips within a connection. Proxy developers should be aware of these limitations, anticipate the potential exploitation of encapsulated TLS handshakes by the censors, and equip their tools with proactive countermeasures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6ad3caeb-5326-496d-9397-60b34137ce71Cited by top-tier papers10
- Bridging Barriers: A Survey of Challenges and Priorities in the Censorship Circumvention LandscapeDiwen Xue, Anna Ablove, Reethika Ramesh, Grace Kwak Danciu et al.USENIX Security 2024 · 7 citations
- SpotProxy: Rediscovering the Cloud for Censorship CircumventionPatrick Tser Jern Kon, Sina Kamali, Jinyu Pei, Diogo Barradas et al.USENIX Security 2024 · 7 citations
- IntraGuard: Committee-Side Defenses Against Review Outsourcing to Commercial ChatbotsOubo Ma, Ruixiao Lin, Jiahao Chen, Yuan Su et al.CCS 2026 · 2 citations
- MVPNalyzer: An Investigative Framework for Auditing the Security & Privacy of Mobile VPNsWayne Wang, Aaron Ortwein, Enrique Sobrados, Robert Stanley et al.NDSS 2026 · 2 citations
- Iris: Expressive Traffic Analysis for the Modern InternetThea Rossman, Diana Qing, Gerry Wan, Zakir DurumericNSDI 2026 · 2 citations
Builds on15
- Global Measurement of DNS ManipulationPaul Pearce, Ben Jones, Frank Li, Roya Ensafi et al.USENIX Security 2017 · 163 citations
- The use of TLS in Censorship CircumventionSergey Frolov, Eric WustrowNDSS 2019 · 97 citations
- ICLab: A Global, Longitudinal Internet Censorship Measurement PlatformArian Akhavan Niaki, Shinyoung Cho, Zachary Weinberg, Nguyen Phong Hoang et al.S&P 2020 · 94 citations
- Augur: Internet-Wide Detection of Connectivity DisruptionsPaul Pearce, Roya Ensafi, Frank Li, Nick Feamster et al.S&P 2017 · 84 citations
- How Great is the Great Firewall? Measuring China's DNS CensorshipNguyen Phong Hoang, Arian Akhavan Niaki, Jakub Dalek, Jeffrey Knockel et al.USENIX Security 2021 · 80 citations
Related papers
- The Discriminative Power of Cross-layer RTTs in Fingerprinting Proxy TrafficDiwen Xue, Robert Stanley, Piyush Kumar, Roya EnsafiNDSS 2025
- Detecting Probe-resistant ProxiesSergey Frolov, Jack Wampler, Eric WustrowNDSS 2020
- OpenVPN is Open to VPN FingerprintingDiwen Xue, Reethika Ramesh, Arham Jain, Michalis Kallitsis et al.USENIX Security 2022
- Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-LayerNiklas Niere, Felix Lange, Robert Merget, Juraj SomorovskyS&P 2025
- Practical Censorship Evasion Leveraging Content Delivery NetworksHadi Zolfaghari, Amir HoumansadrCCS 2016 · 44 citations
