USENIX Security2021Top-tier venue
Balboa: Bobbing and Weaving around Network Censorship
Marc B. Rosen, James Parker, Alex J. Malozemoff
Abstract
We introduce Balboa, a link obfuscation framework for censorship circumvention. Balboa provides a general framework for tunneling data through existing applications. Balboa sits between an application and the operating system, intercepting outgoing network traffic and rewriting it to embed data. To avoid introducing any distinguishable divergence from the expected application behavior, Balboa only rewrites traffic that matches an externally specified traffic model pre-shared between the communicating parties. The traffic model captures some subset of the network traffic (e.g., some subset of music an audio streaming server streams). The sender uses this model to replace outgoing data with a pointer to the associated location in the model and embed data in the freed up space. The receiver then extracts the data, replacing the pointer with the original data from the model before passing the data on to the application. When using TLS, this approach means that application behavior with Balboa is equivalent, modulo small (protocol-dependent) timing differences, to if the application was running without Balboa.
Balboa differs from prior approaches in that it (1) provides a framework for tunneling data through arbitrary (TLSprotected) protocols/applications, and (2) runs the unaltered application binaries on standard inputs, as opposed to most prior tunneling approaches which run the application on nonstandard-and thus potentially distinguishable-inputs.
We present two instantiations of Balboa-one for audio streaming and one for web browsing-and demonstrate the difficulty of identifying Balboa by a machine learning classifier.
- This range corresponds to an HTTP format on the low-end, and an SSH format on the high-end. * * When streaming an audio file encoded at 148 kbps. † When downloading a video with bandwidth capped at 8 Mbps. In general, the goodput depends heavily on the assets being accessed by the client, and may be much lower, or higher, than the number reported here.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fa087de0-2b0b-474c-8c90-70dad0864ff0Cited by top-tier papers5
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- NetShaper: A Differentially Private Network Side-Channel Mitigation SystemAmir Sabzi, Rut Vora, Swati Goswami, Margo I. Seltzer et al.USENIX Security 2024 · 7 citations
- Huma: Censorship Circumvention via Web Protocol Tunneling with Deferred Traffic ReplacementSina Kamali, Diogo BarradasNDSS 2026 · 1 citation
- Telepath: A Minecraft-based Covert Communication SystemZhen Sun, Vitaly ShmatikovS&P 2023
- Discop: Provably Secure Steganography in Practice Based on "Distribution Copies"Jinyang Ding, Kejiang Chen, Yaofei Wang, Na Zhao et al.S&P 2023
Builds on5
- The use of TLS in Censorship CircumventionSergey Frolov, Eric WustrowNDSS 2019 · 97 citations
- Effective Detection of Multimedia Protocol Tunneling using Machine LearningDiogo Barradas, Nuno Santos, Luís E. T. RodriguesUSENIX Security 2018 · 69 citations
- The Waterfall of Liberty: Decoy Routing Circumvention that Resists Routing AttacksMilad Nasr, Hadi Zolfaghari, Amir HoumansadrCCS 2017 · 43 citations
- Poking a Hole in the Wall: Efficient Censorship-Resistant Internet Communications by Parasitizing on WebRTCDiogo Barradas, Nuno Santos, Luís E. T. Rodrigues, Vítor NunesCCS 2020 · 41 citations
- Slitheen: Perfectly Imitated Decoy Routing through Traffic ReplacementCecylia Bocovich, Ian GoldbergCCS 2016 · 40 citations
Related papers
- Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-LayerNiklas Niere, Felix Lange, Robert Merget, Juraj SomorovskyS&P 2025
- Fingerprinting Obfuscated Proxy Traffic with Encapsulated TLS HandshakesDiwen Xue, Michalis Kallitsis, Amir Houmansadr, Roya EnsafiUSENIX Security 2024 · 24 citations
- Practical Censorship Evasion Leveraging Content Delivery NetworksHadi Zolfaghari, Amir HoumansadrCCS 2016 · 44 citations
- CircumVolve: Automated Discovery of Censorship Evasion Strategies Using Large Language ModelsAli Zohaib, Jackson Sippe, Jade Sheffey, Mingshi Wu et al.CCS 2026
- How the Great Firewall of China Detects and Blocks Fully Encrypted TrafficMingshi Wu, Jackson Sippe, Danesh Sivakumar, Jack Burg et al.USENIX Security 2023
