How the Great Firewall of China Detects and Blocks Fully Encrypted Traffic
Mingshi Wu, Jackson Sippe, Danesh Sivakumar, Jack Burg, Peter Anderson, Xiaokang Wang, Kevin Bock, Amir Houmansadr, Dave Levin, Eric Wustrow
摘要
One of the cornerstones in censorship circumvention is fully encrypted protocols, which encrypt every byte of the payload in an attempt to "look like nothing". In early November 2021, the Great Firewall of China (GFW) deployed a new censorship technique that passively detects-and subsequently blocksfully encrypted traffic in real time. The GFW's new censorship capability affects a large set of popular censorship circumvention protocols, including but not limited to Shadowsocks, VMess, and Obfs4. Although China had long actively probed such protocols, this was the first report of purely passive detection, leading the anti-censorship community to ask how detection was possible.
In this paper, we measure and characterize the GFW's new system for censoring fully encrypted traffic. We find that, instead of directly defining what fully encrypted traffic is, the censor applies crude but efficient heuristics to exempt traffic that is unlikely to be fully encrypted traffic; it then blocks the remaining non-exempted traffic. These heuristics are based on the fingerprints of common protocols, the fraction of set bits, and the number, fraction, and position of printable ASCII characters. Our Internet scans reveal what traffic and which IP addresses the GFW inspects. We simulate the inferred GFW's detection algorithm on live traffic at a university network tap to evaluate its comprehensiveness and false positives. We show evidence that the rules we inferred have good coverage of what the GFW actually uses. We estimate that, if applied broadly, it could potentially block about 0.6% of normal Internet traffic as collateral damage.
Our understanding of the GFW's new censorship mechanism helps us derive several practical circumvention strategies. We responsibly disclosed our findings and suggestions to the developers of different anti-censorship tools, helping millions of users successfully evade this new form of blocking.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper24
- Fingerprinting Obfuscated Proxy Traffic with Encapsulated TLS HandshakesDiwen Xue, Michalis Kallitsis, Amir Houmansadr, Roya EnsafiUSENIX Security 2024 · 被引用 24 次
- GFWeb: Measuring the Great Firewall's Web Censorship at ScaleNguyen Phong Hoang, Jakub Dalek, Masashi Crete-Nishihata, Nicolas Christin 等USENIX Security 2024 · 被引用 22 次
- Bridging Barriers: A Survey of Challenges and Priorities in the Censorship Circumvention LandscapeDiwen Xue, Anna Ablove, Reethika Ramesh, Grace Kwak Danciu 等USENIX Security 2024 · 被引用 7 次
- SpotProxy: Rediscovering the Cloud for Censorship CircumventionPatrick Tser Jern Kon, Sina Kamali, Jinyu Pei, Diogo Barradas 等USENIX Security 2024 · 被引用 7 次
- Identifying VPN Servers through Graph-Represented BehaviorsChenxu Wang, Jiangyi Yin, Zhao Li, Hongbo Xu 等WWW 2024 · 被引用 6 次
它引用的顶会 Paper6
- The use of TLS in Censorship CircumventionSergey Frolov, Eric WustrowNDSS 2019 · 被引用 97 次
- SoK: Towards Grounding Censorship Circumvention in EmpiricismMichael Carl Tschantz, Sadia Afroz, anonymous, Vern PaxsonS&P 2016 · 被引用 89 次
- Quack: Scalable Remote Measurement of Application-Layer CensorshipBenjamin VanderSloot, Allison McDonald, Will Scott, J. Alex Halderman 等USENIX Security 2018 · 被引用 66 次
- LZR: Identifying Unexpected Internet ServicesLiz Izhikevich, Renata Teixeira, Zakir DurumericUSENIX Security 2021 · 被引用 63 次
- Conjure: Summoning Proxies from Unused Address SpaceSergey Frolov, Jack Wampler, Sze Chuen Tan, J. Alex Halderman 等CCS 2019 · 被引用 28 次
相关 Paper
- Exposing and Circumventing SNI-based QUIC Censorship of the Great Firewall of ChinaAli Zohaib, Qiang Zao, Jackson Sippe, Abdulrahman Alaraj 等USENIX Security 2025
- Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-LayerNiklas Niere, Felix Lange, Robert Merget, Juraj SomorovskyS&P 2025
- Chinese Wall or Swiss Cheese? Keyword filtering in the Great Firewall of ChinaZachary Weinberg, Diogo Barradas, Nicolas ChristinWWW 2021 · 被引用 33 次
- GET /out: Automated Discovery of Application-Layer Censorship Evasion StrategiesMichael Harrity, Kevin Bock, Frederick Sell, Dave LevinUSENIX Security 2022
- CircumVolve: Automated Discovery of Censorship Evasion Strategies Using Large Language ModelsAli Zohaib, Jackson Sippe, Jade Sheffey, Mingshi Wu 等CCS 2026
