geedge.lantern.io

Defenses

WebRTC-based pluggable transport

also: Snowflake, broflake, Unbounded

evaluation medium

An internal MESA Lab research survey ("审查规避调研报告") catalogs current academic circumvention research the lab tracks as detection R&D input: Geneva/GET-out packet-mutation evasion, the WebRTC-based Protozoa tunnel, and CDN-based domain shadowing combined with domain fronting -- evidence the lab actively monitors the circumvention literature rather than working purely from first principles.

generic
deployment high

A weekly "新疆移动流量分析报告" (Xinjiang Mobile Traffic Analysis Report), authored by the "运营商前端分析团队" (Carrier Front-End Analysis Team), directly ties the SNI/Server-IP overseas- APP report format to the China Mobile Xinjiang branch specifically, and states the pipeline identifies 126 distinct application-layer protocols including multi-layer tunnel nesting such as STUN.DTLS and STUN.RTP.RTCP.DTLS — i.e. it decomposes and classifies nested WebRTC-style transport stacks, not just top-level TLS/QUIC.

cn traffic-shapedpi
evaluation low

An internal MESA literature-review report surveys published GFW-evasion research the team is tracking -- including Geneva-style TCB desynchronization, application-layer field-mutation evasion, CDN-based Domain Fronting/CacheBrowser/CDNReaper/Domain Shadowing/DfDs, and traffic-mimicry tools including the WebRTC-parasitizing tool Protozoa and the TLS-mimicking Trojan protocol -- indicating these specific circumvention technique families are on MESA's active R&D radar.

generic
detection medium

A MESA Lab git repo (wangmeiqi/obfs4_meek_snowflake) trains closed-world Deep Fingerprinting (DF) website-fingerprinting classifiers (ClosedWorld_DF_NoDef.py) using pre-trained Keras models specifically for Tor's obfs4 pluggable transport, meek domain-fronting, and Snowflake -- the same transport families Lantern's own circumvention stack draws on.

website-fingerprintml-classifiertraffic-shape
detection medium

An internal MESA Lab research survey dedicated to Snowflake reviews five external papers on fingerprinting/blocking Snowflake and WebRTC-based transports, including a 2023 CSCWD paper that fingerprints Snowflake's broker-contact requests (disguised as HTTPS) via packet size, direction, timing, and network speed to distinguish them from ordinary web requests, and a 2020 paper claiming 100% identification of Snowflake DTLS handshakes against Facebook Messenger/Hangouts/ Discord WebRTC traffic in a closed-world test — annotated throughout with the MESA reviewer's own critical commentary on each method's weaknesses (e.g. sensitivity to user geography/network, only tested at host/LAN vantage points rather than backbone).

cn tls-fingerprinttraffic-shape
detection medium

Meeting notes from a MESA "VPN基础设施" (VPN infrastructure) project log explicit work sessions on "cloud services & CDN IP range" cataloging, "SS [Shadowsocks] experiments," and "Snowflake, SS organizing" across consecutive weeks in mid-2022, alongside a separately named "网络公害" ("internet nuisance/hazard") project.

generic