FINDING · DETECTION

A protocol-agnostic classifier that identifies RFC-mandated TCP behaviors (three-way handshake, 500ms ACK, 2×RMSS acknowledgement) leaking through UDP-based VPN tunnels achieves a false positive rate of 0.11–0.29% on real campus traffic, an order of magnitude lower than ML-based VPN detection techniques (FPR 1.4–5.5%) and on par with the GFW's estimated heuristic FPR of 0.6%.

From 2024-hanlon-detectingDetecting VPN Traffic through Encapsulated TCP Behavior · §3–§4.2 · 2024 · Free and Open Communications on the Internet

Implications

Tags

censors
genericcn
techniques
traffic-shapedpi
defenses
randomizationtunneling

Extracted by claude-sonnet-4-6 — review before relying.