测试表明,加密全包的翻墙协议在常规网络流中易被机器学习识别。
Efficacy of Full-Packet Encryption in Mitigating Protocol Detection for Evasive Virtual Private Networks
- 用机器学习模型分析全包加密翻墙流量,发现其在正常网络中可被精准识别。
- 相比随机噪声,该协议在真实网络流中检测准确率超90%且误伤极小。
- 适合关注网络安全对抗、网络审查技术的读者,尤其对隐私保护研究者有价值。
现代隐蔽型虚拟私人网络(VPN)采用全包加密技术,将流量伪装成网络中的随机噪声,以规避基于协议特征的审查。传统封禁方式需大量误伤,因其他随机流量也会被阻断。本文针对完全加密的隐蔽协议ACC(Aggressive Circumvention of Censorship)进行测试,该协议融合了多种现有隐蔽协议策略。实验表明,尽管ACC在与随机噪声对比时能有效抵抗检测,但在真实网络流量流中,使用多种机器学习分类模型可实现高精度识别,且误伤极低。这说明当前国家层面部署的审查技术虽难以应对,但基于数据包的协议识别方法已具备可行性。
原文摘要 · Abstract (English)
Full-packet encryption is a technique used by modern evasive Virtual Private Networks (VPNs) to avoid protocol-based flagging from censorship models by disguising their traffic as random noise on the network. Traditional methods for censoring full-packet-encryption based VPN protocols requires assuming a substantial amount of collateral damage, as other non-VPN network traffic that appears random will be blocked. I tested several machine learning-based classification models against the Aggressive Circumvention of Censorship (ACC) protocol, a fully-encrypted evasive VPN protocol which merges strategies from a wide variety of currently in-use evasive VPN protocols. My testing found that while ACC was able to survive our models when compared to random noise, it was easily detectable with minimal collateral damage using several different machine learning models when within a stream of regular network traffic. While resistant to the current techniques deployed by nation-state censors, the ACC protocol and other evasive protocols are potentially subject to packet-based protocol identification utilizing similar classification models.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。