USENIX Security2021Top-tier venue
Domain Shadowing: Leveraging Content Delivery Networks for Robust Blocking-Resistant Communications
Mingkui Wei
Abstract
We debut domain shadowing, a novel censorship evasion technique leveraging content delivery networks (CDNs). Domain shadowing exploits the fact that CDNs allow their customers to claim arbitrary domains as the back-end. By setting the front-end of a CDN service as an allowed domain and the back-end a blocked one, a censored user can access resources of the blocked domain with all "indicators", including the connecting URL, the SNI of the TLS connection, and the Host header of the HTTP(S) request, appear to belong to the allowed domain. Furthermore, we demonstrate that domain shadowing can be proliferated by domain fronting, a censorship evasion technique popularly used a few years ago, making it even more difficult to block. Compared with existing censorship evasion solutions, domain shadowing is lightweight, incurs negligible overhead, and does not require dedicated third-party support. As a proof of concept, we implemented domain shadowing as a Firefox browser extension and demonstrated its capability in circumventing censorship within a heavily censored country known by its strict censorship policies and advanced technologies.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b5f87d00-2b0e-4064-b168-7dfe9cb2dd4dCited by top-tier papers7
- SpotProxy: Rediscovering the Cloud for Censorship CircumventionPatrick Tser Jern Kon, Sina Kamali, Jinyu Pei, Diogo Barradas et al.USENIX Security 2024 · 7 citations
- NetShuffle: Circumventing Censorship with Shuffle Proxies at the EdgePatrick Tser Jern Kon, Aniket Gattani, Dhiraj Saharia, Tianyu Cao et al.S&P 2024 · 6 citations
- Discovering and Measuring CDNs Prone to Domain FrontingKarthika Subramani, Roberto Perdisci, Pierros-Christos Skafidas, Manos AntonakakisWWW 2024 · 5 citations
- CDN Cannon: Exploiting CDN Back-to-Origin Strategies for Amplification AttacksZiyu Lin, Zhiwei Lin, Ximeng Liu, Jianjun Chen et al.USENIX Security 2024 · 5 citations
- Huma: Censorship Circumvention via Web Protocol Tunneling with Deferred Traffic ReplacementSina Kamali, Diogo BarradasNDSS 2026 · 1 citation
Builds on3
- The Security Impact of HTTPS InterceptionZakir Durumeric, Zane Ma, Drew Springall, Richard Barnes et al.NDSS 2017 · 161 citations
- Practical Censorship Evasion Leveraging Content Delivery NetworksHadi Zolfaghari, Amir HoumansadrCCS 2016 · 44 citations
- Melting Pot of Origins: Compromising the Intermediary Web Services that Rehost WebsitesTakuya Watanabe, Eitaro Shioji, Mitsuaki Akiyama, Tatsuya MoriNDSS 2020
Related papers
- GET /out: Automated Discovery of Application-Layer Censorship Evasion StrategiesMichael Harrity, Kevin Bock, Frederick Sell, Dave LevinUSENIX Security 2022
- MassBrowser: Unblocking the Censored Web for the Masses, by the MassesMilad Nasr, Hadi Zolfaghari, Amir Houmansadr, Amirhossein GhafariNDSS 2020
- Don't Let One Rotten Apple Spoil the Whole Barrel: Towards Automated Detection of Shadowed DomainsDaiping Liu, Zhou Li, Kun Du, Haining Wang et al.CCS 2017 · 60 citations
- Temporal CDN-Convex Lens: A CDN-Assisted Practical Pulsing DDoS AttackRun Guo, Jianjun Chen, Yihang Wang, Keran Mu et al.USENIX Security 2023
- Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-LayerNiklas Niere, Felix Lange, Robert Merget, Juraj SomorovskyS&P 2025
