Proxy Detection via Passive Traffic Analysis and Fingerprinting
No Thumbnail Available
Date
2026
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Saudi Digital Library
Abstract
In this thesis, I study proxy detection in two settings: Internet censorship and application provider access control. Both impose restrictions on users’ access to content and services, and users employ proxies to bypass these restrictions. This interaction forms a continuous cat and mouse game, where advances in evasion drive advances in detection, and vice
versa.
In the censorship game, detection must work at national scale. The literature identifies a research-to-practice gap. Research proposes methods that are complex and costly to deploy. I take this operational constraint as a design requirement and address the problem from two novel angles. The first angle analyzes the network path to identify practical detection points that censors can leverage. I uncover two previously unexplored detection points: the home router and domestic web-tracking infrastructure. I show how they enable scalable detection. The second angle is the first study to examine circumvention tool architectures from a detection perspective. It reveals a previously unexploited structural property that
enables passive detection. This property requires architectural changes to evade. All three methods are passive, obfuscation-agnostic, and designed for deployment at scale.
In the application provider game, the server must answer a binary question: is this connection proxied? Residential proxy providers defeat existing detection methods. Their proxy IP addresses are residential and absent from proxy databases. Their global scale allows users to select geographically close proxies and evade RTT-based detection. The proxy runs on a residential device that also generates legitimate traffic. As a result, the connection blends with normal user traffic. I address this problem from two angles. The first is the largest measurement of the residential proxy ecosystem to date, with novel passive device-level fingerprinting. The second is a new detection primitive that exploits a structural property of proxy connections. It detects proxies that IP reputation and RTT-based methods miss.
In summary, this thesis makes five contributions across two settings. For Internet censorship, I present three passive detection methods, each with a characterization of countermeasures. For the application provider, I present the largest residential proxy measurement to date and a detection primitive based on cross-layer OS fingerprinting.
Description
تتضمن هذه الرسالة (الأطروحة) موادًا علمية قيد التقديم حاليًا للنشر، وسيتم نشر جزء منها في مؤتمر علمي ومجلة علمية محكّمة. وحفاظًا على أصالة هذا العمل قبل نشره رسميًا، ألتمس من المكتبة حجب الرسالة عن الإتاحة العامة لمدة ثمانية عشر (18) شهرًا من تاريخ إيداعها. وأشكر المكتبة على تفهمها وتعاونها في هذا الطلب.
Keywords
Proxy Detection, VPN Detection, Residential Proxy, Measurement, Traffic Analysis, Fingerprinting
