论文标题
评估雪花作为无法区分的审查制度规避工具
Evaluating Snowflake as an Indistinguishable Censorship Circumvention Tool
论文作者
论文摘要
TOR是规避审查制度的最著名工具。不幸的是,已证明使用深包检查可检测到TOR流量。 WEBRTC是一种流行的Web框架工作,可以启用浏览器到浏览器连接。 Snowflake是一种可实现的新型运输,它利用WebRTC将Tor客户端连接到TOR网络。从理论上讲,雪花是与其他WEBRTC服务没有区别的。在本文中,我们评估了雪花的不可区分性。我们从Snowflake,Facebook Messenger,Google Hangouts和Discord WebRTC连接中收集了6,500多个DTLS握手,并表明雪花在这些应用中可识别为100%的精度。我们表明,包括提供的扩展名和握手中的数据包数量,可以区分这些服务之间的几个功能。最后,我们建议提出改善雪花识别性的建议。我们已公开提供数据集。
Tor is the most well-known tool for circumventing censorship. Unfortunately, Tor traffic has been shown to be detectable using deep-packet inspection. WebRTC is a popular web frame-work that enables browser-to-browser connections. Snowflake is a novel pluggable transport that leverages WebRTC to connect Tor clients to the Tor network. In theory, Snowflake was created to be indistinguishable from other WebRTC services. In this paper, we evaluate the indistinguishability of Snowflake. We collect over 6,500 DTLS handshakes from Snowflake, Facebook Messenger, Google Hangouts, and Discord WebRTC connections and show that Snowflake is identifiable among these applications with 100% accuracy. We show that several features, including the extensions offered and the number of packets in the handshake, distinguish Snowflake among these services. Finally, we suggest recommendations for improving identification resistance in Snowflake. We have made the dataset publicly available.