FINDING · DETECTION

The encapsulated TCP three-way handshake (3WHS) is detected in 80.59% of VPN flows but only 0.33% of plain UDP flows, making it—on its own—a near-practical VPN detector with 0.33% FPR; its presence is required by the classifier regardless of the compliance-rate threshold t.

From 2024-hanlon-detectingDetecting VPN Traffic through Encapsulated TCP Behavior · §4.2 Feature Importance · 2024 · Free and Open Communications on the Internet

Implications

Tags

censors
generic
techniques
traffic-shape
defenses
randomizationtunneling

Extracted by claude-sonnet-4-6 — review before relying.