FINDING · EVALUATION

Web browsing VPN traffic achieves only 32.35–42.44% TPR—far below SSH (99.43–99.56%) and file transfer (83.95–99.73%)—because DNS queries interleaved with TCP streams disrupt detection of the encapsulated 3WHS, confirming that connection multiplexing is a naturally occurring and effective evasion for web-browsing workloads.

From 2024-hanlon-detectingDetecting VPN Traffic through Encapsulated TCP Behavior · §4.2 Overall Classifier Results · 2024 · Free and Open Communications on the Internet

Implications

Tags

censors
generic
techniques
traffic-shape
defenses
tunneling

Extracted by claude-sonnet-4-6 — review before relying.