Indistinguishability of Traffic by Open TLS Parameters with Encrypted ClientHello

D. R. Shamsimukhametov,A. A. Kurapov,M. V. Liubogoshchev,E. M. Khorov
DOI: https://doi.org/10.1134/s1064226923120173
2024-03-02
Journal of Communications Technology and Electronics
Abstract:Traffic Classification (TC) is a key part of many network frameworks that provide Quality of Service (QoS) for traffic. Encrypted TC algorithms often use the Server Name Indication (SNI) field, which indicates the domain name of the server to which the client establishes a connection, and which is a clear marker of the traffic category. However, the new Encrypted ClientHello (ECH) extension, which supplements the TLS 1.3 protocol significantly complicates TC because most of the messages of the TLS handshake become encrypted, including SNI. With ECH, the accuracy of TC algorithms that use open TLS parameters significantly degrades. This paper studies the indistinguishability of the encrypted traffic considering the remaining open TLS parameters.
telecommunications,engineering, electrical & electronic
What problem does this paper attempt to address?