Proxy Detection via Passive Traffic Analysis and Fingerprinting

dc.contributor.advisorHarfoush, Khaled
dc.contributor.advisorViniotis, Ioannis
dc.contributor.authorAlmutairi, Sultan Saud M
dc.date.accessioned2026-07-29T13:09:37Z
dc.date.issued2026
dc.descriptionتتضمن هذه الرسالة (الأطروحة) موادًا علمية قيد التقديم حاليًا للنشر، وسيتم نشر جزء منها في مؤتمر علمي ومجلة علمية محكّمة. وحفاظًا على أصالة هذا العمل قبل نشره رسميًا، ألتمس من المكتبة حجب الرسالة عن الإتاحة العامة لمدة ثمانية عشر (18) شهرًا من تاريخ إيداعها. وأشكر المكتبة على تفهمها وتعاونها في هذا الطلب.
dc.description.abstractIn this thesis, I study proxy detection in two settings: Internet censorship and application provider access control. Both impose restrictions on users’ access to content and services, and users employ proxies to bypass these restrictions. This interaction forms a continuous cat and mouse game, where advances in evasion drive advances in detection, and vice versa. In the censorship game, detection must work at national scale. The literature identifies a research-to-practice gap. Research proposes methods that are complex and costly to deploy. I take this operational constraint as a design requirement and address the problem from two novel angles. The first angle analyzes the network path to identify practical detection points that censors can leverage. I uncover two previously unexplored detection points: the home router and domestic web-tracking infrastructure. I show how they enable scalable detection. The second angle is the first study to examine circumvention tool architectures from a detection perspective. It reveals a previously unexploited structural property that enables passive detection. This property requires architectural changes to evade. All three methods are passive, obfuscation-agnostic, and designed for deployment at scale. In the application provider game, the server must answer a binary question: is this connection proxied? Residential proxy providers defeat existing detection methods. Their proxy IP addresses are residential and absent from proxy databases. Their global scale allows users to select geographically close proxies and evade RTT-based detection. The proxy runs on a residential device that also generates legitimate traffic. As a result, the connection blends with normal user traffic. I address this problem from two angles. The first is the largest measurement of the residential proxy ecosystem to date, with novel passive device-level fingerprinting. The second is a new detection primitive that exploits a structural property of proxy connections. It detects proxies that IP reputation and RTT-based methods miss. In summary, this thesis makes five contributions across two settings. For Internet censorship, I present three passive detection methods, each with a characterization of countermeasures. For the application provider, I present the largest residential proxy measurement to date and a detection primitive based on cross-layer OS fingerprinting.
dc.format.extent98
dc.identifier.urihttps://hdl.handle.net/20.500.14154/79686
dc.language.isoen_US
dc.publisherSaudi Digital Library
dc.subjectProxy Detection
dc.subjectVPN Detection
dc.subjectResidential Proxy
dc.subjectMeasurement
dc.subjectTraffic Analysis
dc.subjectFingerprinting
dc.titleProxy Detection via Passive Traffic Analysis and Fingerprinting
dc.typeThesis
sdl.degree.departmentElectrical and Computer Engineering
sdl.degree.disciplineComputer Engineering
sdl.degree.grantorNorth Carolina State University
sdl.degree.namePhD

Files

Original bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
SACM-Dissertation.pdf
Size:
2.42 MB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.61 KB
Format:
Item-specific license agreed to upon submission
Description:

Copyright owned by the Saudi Digital Library (SDL) © 2026