WebRTC-based pluggable transport
also: Snowflake, broflake, Unbounded
An internal MESA Lab research survey ("审查规避调研报告") catalogs current academic circumvention research the lab tracks as detection R&D input: Geneva/GET-out packet-mutation evasion, the WebRTC-based Protozoa tunnel, and CDN-based domain shadowing combined with domain fronting -- evidence the lab actively monitors the circumvention literature rather than working purely from first principles.
A weekly "新疆移动流量分析报告" (Xinjiang Mobile Traffic Analysis Report), authored by the "运营商前端分析团队" (Carrier Front-End Analysis Team), directly ties the SNI/Server-IP overseas- APP report format to the China Mobile Xinjiang branch specifically, and states the pipeline identifies 126 distinct application-layer protocols including multi-layer tunnel nesting such as STUN.DTLS and STUN.RTP.RTCP.DTLS — i.e. it decomposes and classifies nested WebRTC-style transport stacks, not just top-level TLS/QUIC.
An internal MESA literature-review report surveys published GFW-evasion research the team is tracking -- including Geneva-style TCB desynchronization, application-layer field-mutation evasion, CDN-based Domain Fronting/CacheBrowser/CDNReaper/Domain Shadowing/DfDs, and traffic-mimicry tools including the WebRTC-parasitizing tool Protozoa and the TLS-mimicking Trojan protocol -- indicating these specific circumvention technique families are on MESA's active R&D radar.
A MESA Lab git repo (wangmeiqi/obfs4_meek_snowflake) trains closed-world Deep Fingerprinting (DF) website-fingerprinting classifiers (ClosedWorld_DF_NoDef.py) using pre-trained Keras models specifically for Tor's obfs4 pluggable transport, meek domain-fronting, and Snowflake -- the same transport families Lantern's own circumvention stack draws on.
An internal MESA Lab research survey dedicated to Snowflake reviews five external papers on fingerprinting/blocking Snowflake and WebRTC-based transports, including a 2023 CSCWD paper that fingerprints Snowflake's broker-contact requests (disguised as HTTPS) via packet size, direction, timing, and network speed to distinguish them from ordinary web requests, and a 2020 paper claiming 100% identification of Snowflake DTLS handshakes against Facebook Messenger/Hangouts/ Discord WebRTC traffic in a closed-world test — annotated throughout with the MESA reviewer's own critical commentary on each method's weaknesses (e.g. sensitivity to user geography/network, only tested at host/LAN vantage points rather than backbone).
Meeting notes from a MESA "VPN基础设施" (VPN infrastructure) project log explicit work sessions on "cloud services & CDN IP range" cataloging, "SS [Shadowsocks] experiments," and "Snowflake, SS organizing" across consecutive weeks in mid-2022, alongside a separately named "网络公害" ("internet nuisance/hazard") project.