Application Awareness in Censorship Circumvention Systems
Internet censorship circumvention systems rely on cover applications to conceal the existence of their communication: covert data is tunneled through the encrypted network channel of the cover applications to provide network-level unobservability. However, recently proposed systems are not aware of the cover application semantics, making them vulnerable to adversaries that can observe the application-level behavior of cover applications. In this thesis, I present my Ph.D. research on new classes of attacks on censorship circumvention systems that exploit the lack of application awareness in existing designs, as well as the mitigation of these attacks. We first demonstrate a new type of active attack we call "differential degradation." These attacks exploit the discrepancies between the network requirements of the cover application and those of the circumvention system, allowing adversaries to detect and block state-of-the-art systems that resist network traffic analysis-based attacks. Differential degradation doesn't require complex multi-flow measurement or traffic classification, making it feasible for realistic censors at low cost. I'll also discuss the root causes of these vulnerabilities and the trade-offs faced by designers of circumvention systems. Then, we show how a network-based adversary is able to observe a cover application’s events through encrypted traffic flows, and thus can detect the violation of application-specific invariants caused by tunneling data through the cover application using popular content substitution designs. To mitigate the problem, we propose non-disruptive content substitution that does not introduce inconsistencies into the application state. Using this idea, we design and implement Telepath, a Minecraft-based covert communication system that is immune to our attacks while providing resistance to traditional traffic analysis attacks.