NetShuffle: Circumventing Censorship with Shuffle Proxies at the Edge
Patrick Tser Jern Kon, Aniket Gattani, Dhiraj Saharia, Tianyu Cao, Diogo Barradas, Ang Chen
IEEE Symposium on Security and Privacy 2024 · Day 3 · Continental Ballroom 6
Overview
In an era where digital censorship affects over half the world's population, the talk "NetShuffle: Circumventing Censorship with Shuffle Proxies at the Edge" introduces a novel, robust system designed to enhance global internet freedom. Presented by Patrick Tser Jern Kon from the University of Michigan, alongside advisor Ang Chen and collaborators from various institutions, NetShuffle addresses the persistent challenge of nation-state censorship by leveraging a previously underutilized resource: Edge networks. The core innovation lies in dynamically shuffling the IP-to-service mappings within these networks, making it significantly harder for censors to identify and block circumvention proxies without incurring substantial collateral damage.

Key moments
- 0:00 Introduction to censorship and circumvention challenges
- 2:00 Analyzing existing end-user and core network proxies
- 4:00 Proposing Edge networks as a novel support base
- 4:54 NetShuffle's core idea: IP to service mapping shuffle
- 6:00 High-level overview of NetShuffle's operation
- 7:00 NetShuffle's epoch-based IP shuffling mechanism explained
NetShuffle: Circumventing Censorship with Shuffle Proxies at the Edge
Speakers: Patrick Tser Jern Kon, University of Michigan; Aniket Gattani; Dhiraj Saharia; Tianyu Cao; Diogo Barradas; Ang Chen, University of Michigan
Conference: IEEE S&P
YouTube: https://www.youtube.com/watch?v=VZ_Py0E8CSM
Overview
In an era where digital censorship affects over half the world's population, the talk "NetShuffle: Circumventing Censorship with Shuffle Proxies at the Edge" introduces a novel, robust system designed to enhance global internet freedom. Presented by Patrick Tser Jern Kon from the University of Michigan, alongside advisor Ang Chen and collaborators from various institutions, NetShuffle addresses the persistent challenge of nation-state censorship by leveraging a previously underutilized resource: Edge networks. The core innovation lies in dynamically shuffling the IP-to-service mappings within these networks, making it significantly harder for censors to identify and block circumvention proxies without incurring substantial collateral damage.
The talk highlights a critical power imbalance between well-resourced nation-state censors and often volunteer-backed circumvention efforts. Existing solutions, while effective to varying degrees, suffer from limitations related to their support bases – either being easily enumerated (end-user systems) or susceptible to political and business pressures (core networks like CDNs). NetShuffle proposes a new paradigm by positioning shuffle proxies at the edge of campus and enterprise networks, transforming these environments into resilient, high-collateral-damage targets for censors. This approach promises a new level of unblockability, transparent deployment, and efficient resource utilization, fundamentally altering the economics of censorship.
NetShuffle is not just a theoretical concept; it's a working prototype deployed on commodity hardware within a live campus network. Its design demonstrates how a single router at the edge can provide a robust, transparent, and low-resource-footprint circumvention system. By making fine-grained blocking impractical, NetShuffle aims to provide a sustainable and scalable solution for individuals in censored regions to access a free and open internet, marking a significant advancement in the ongoing battle against digital repression.
Background
▶ Watch: Introduction to censorship and circumvention challenges (0:00)
Digital censorship is a pervasive global issue, with nation-states employing sophisticated strategies to control information access. These strategies vary in duration, severity, and technical approach, ranging from pervasive media censorship in countries like Iran to event-specific blocks during political protests in Zimbabwe or Pakistan. The adversaries, often nation-states, wield immense power, deploying sensor filters at arbitrary locations and granularities, running diverse protocols to detect circumvention. In contrast, circumvention efforts typically rely on limited resources and volunteer support from uncensored regions.
The prevailing threat model for circumvention systems involves nation-states that are averse to coarse-grained blocking, such as blocking entire IP address spaces. Such actions often lead to collateral damage, where legitimate, critical services are inadvertently blocked alongside circumvention tools. Consequently, censors increasingly favor fine-grained approaches, targeting specific suspicious endpoints through techniques like IP or DNS-based enumeration attacks.
Traditional censorship circumvention strategies largely rely on two primary support bases:
- End-user systems: These include individual devices running proxies like those found in the Tor anonymity network, Lantern, or browser-based proxies like Snowflake. While they offer a large support base (anyone can run a proxy), they suffer from low collateral damage (blocking an individual laptop's IP doesn't affect critical services) and are easy to enumerate.
- Core networks: This category encompasses large network infrastructure providers such as Content Delivery Networks (CDNs) and Internet Service Providers (ISPs). These networks present a high collateral damage proposition for censors, as blocking an IP address might disrupt numerous legitimate services hosted behind it (in the case of CDNs) or cut off large swathes of benign traffic (for ISPs). However, core networks have a small support base, and individual companies within these networks often have business interests in censoring nations, leading to instances like Microsoft blocking domain fronting years ago. Examples include decoy routing, domain fronting, and domain shadowing.
The critical question posed by the NetShuffle researchers was whether a third, overlooked support base existed. They identified Edge networks – such as campus and enterprise networks – as an ideal middle ground. While some Edge networks currently host proxy services, they often do so by mimicking end-user proxies, thus neglecting their inherent advantages. NetShuffle seeks to harness these advantages: their substantial collateral damage potential (hosting important services) and their substantial support base. A conservative estimate suggests there are around 48,000 autonomous systems representing Edge networks, offering a decentralized governance model where the blocking of a single Edge network would not cripple the entire circumvention system. This recognition forms the foundational premise for NetShuffle's design.
Key Findings
▶ Watch: Proposing Edge networks as a novel support base (4:00)
NetShuffle's primary contribution is the identification and strategic utilization of Edge networks as a novel and robust support base for censorship circumvention. The research posits that these networks, which sit between individual end-user systems and large core networks, possess unique characteristics that make them ideal for resisting fine-grained blocking by nation-state censors. The key findings and associated benefits are:
- New Support Base: Edge networks, encompassing campus and enterprise networks, represent an estimated 48,000 autonomous systems. Unlike end-user systems, they host critical services, leading to substantial collateral damage if blocked. Unlike core networks, their decentralized nature means that the loss of one Edge network does not significantly impact the overall circumvention system. This offers a more resilient and scalable support base for volunteers.
- Enhanced Unblockability through IP Shuffling: The central technical innovation of NetShuffle is to prevent fine-grained blocking by continuously shuffling the IP-to-service mapping of services within an Edge network. This means that a proxy service, represented by a specific hostname (e.g.,
beta.shu.edu), will appear to clients with different external IP addresses over short time periods (epochs). For a censor, this implies that blocking a single proxy IP address is effectively equivalent to blocking the entire Edge network, as the "suspicious" IP might soon host a legitimate service. This dramatically raises the cost of censorship for nation-states, pushing them towards incurring unacceptable collateral damage.
- Drop-in Deployment: NetShuffle is designed for ease of integration into existing network infrastructure. It requires only a single router at the edge of the Edge network to function. This minimal hardware requirement and simplified setup make it accessible for deployment by network administrators in campus or enterprise environments. The talk notes that a prototype was set up on a live campus network in "one person per day" of effort, running on a network in use for over five years.
- Transparent Shuffle: A crucial design principle is that NetShuffle operates without requiring any impact or changes on either the client applications or the services residing within the Edge network. Clients connect as usual, and services continue to operate normally, unaware of the underlying IP shuffling mechanism. This transparency is vital for widespread adoption and minimal operational overhead.
- Low Resource Footprint: The NetShuffle system is engineered to have a low resource usage on the edge router, ensuring that the router can efficiently handle other network programs and functions. This focus on efficiency makes NetShuffle a practical and sustainable solution for real-world deployments.
In summary, NetShuffle's key findings revolve around its ability to engage a new, robust support base in Edge networks and provide a mechanism for unblockability that makes fine-grained censorship economically unfeasible for nation-states. Its design emphasizes practical deployment, transparency, and efficiency, setting a new standard for censorship circumvention systems.
Technical Deep Dive
▶ Watch: NetShuffle's core idea: IP to service mapping shuffle (4:54)
NetShuffle's architecture is meticulously designed to achieve its goal of dynamic IP-to-service mapping within Edge networks, thereby frustrating fine-grained censorship. The system relies on a few core components and addresses several complex networking challenges.
Basic NetShuffle Workflow
The fundamental operation of NetShuffle involves Alice, a user in a censored region, accessing a blocked website via a proxy server hosted within an Edge network.
- Proxy Request: Alice first utilizes existing proxy distribution infrastructure to obtain a proxy hostname (e.g.,
beta.shu.edu) and a shared secret. - DNS Resolution: Alice resolves the proxy hostname using a DNS server. Crucially, this DNS server is integrated with NetShuffle and returns an external IP address that is dynamically mapped to the proxy service.
- Access Request: Alice sends packets to this external IP address.
- NetShuffle Switch Interception: These packets are intercepted by the NetShuffle switch, which is deployed at the edge of the Edge network. The switch performs a critical translation: it converts the external IP address to an internal IP address that represents the true location of the proxy server within the Edge network.
- Redirection and Forwarding: The NetShuffle switch redirects the packets to the proxy server using its internal IP. The proxy server then forwards the traffic to the actual destination (e.g., Facebook), completing the cycle.
A cornerstone of NetShuffle's design is the continuous shuffling of mapping tables. The system maintains two primary mapping tables: one linking hostnames to external IP addresses (managed by the DNS server) and another linking external IP addresses to internal IP addresses (managed by the NetShuffle switch). These mappings are updated periodically in discrete time intervals called epochs.
Epoch-based Shuffling
The core mechanism for confusing censors is the dynamic change of external IP addresses associated with a given proxy hostname. For example, in Epoch 1, beta.shu.edu might resolve to 93.184.216.1. In Epoch 2, the same hostname might resolve to 93.184.216.25. Both external IPs, however, map to the same internal IP address (e.g., 10.0.0.200) representing the actual proxy service. The intent is that an external IP address that once pointed to a circumvention proxy might later point to a legitimate service, making static IP blocking ineffective and costly.
Addressing Network Asynchrony
A significant challenge in dynamic IP shuffling is network asynchrony. Factors like DNS Time-To-Live (TTL) values, DNS caching, and general network propagation delays mean that a client might resolve an IP address in one epoch but send traffic to it in a subsequent epoch when the mapping has changed. In a naive implementation, this could lead to clients accessing the wrong service or experiencing connection failures.
NetShuffle's solution is the asynchronous Network Shuffle. The key idea here is to maintain outdated mappings for more than a single epoch. Instead of immediately discarding old mappings, the NetShuffle switch retains them for a configurable duration. The IP space is partitioned into r segments, and in each epoch, a new mapping permutation is computed for one partition, while the mappings for the other r-1 partitions become "old" but are still maintained. This allows for smooth transitions and accommodates network delays, ensuring that clients with slightly delayed DNS resolutions or connection initiations can still reach the correct service. For instance, an r-way partition would mean that the switch maintains one latest mapping table and r-1 outdated mapping tables.
Solving Large IP Slack Requirements with Shuffle Compaction
The asynchronous shuffling, while robust, introduces another problem: it requires a substantial pool of free IP addresses (IPs not actively used by services) to accommodate the multiple partitions and their mappings. In a naive asynchronous shuffle, each partition would need a one-to-one mapping to all services in the Edge network, consuming a large number of external IPs. To address this, NetShuffle introduces Shuffle compaction, an optimization with two versions:
- Non-hosting Protocol Case: For services that do not rely on a hostname (e.g., SSH, FTP), NetShuffle can map a single external IP address to multiple internal IP addresses, provided these internal services are listening on different ports. For example,
93.184.216.110could map to10.0.0.200:22(SSH) and10.0.0.201:21(FTP). This significantly reduces the external IP address requirement.
- Hosting Protocol Case: For services that rely on hostnames (e.g., HTTP/S, where multiple websites can share an IP via virtual hosting), NetShuffle can map a single external IP address to multiple services even if they listen on the same internal port (e.g., Port 443 for HTTPS). This requires disambiguation based on the hostname carried within the connection.
- TLS SNI Header: NetShuffle relies on extracting the Server Name Indication (SNI) header from TLS connections, which contains the hostname the client intends to connect to.
- Switch-mediated TCP Handshake: Extracting the SNI header requires the NetShuffle switch to mediate the TCP handshake, which is complex because programmable hardware switches typically do not have a full TCP/IP stack. The implementation involves carefully designed packet processing logic within the switch's data plane.
- Accelerated Hostname Extraction: To ensure high performance, the system accelerates hostname extraction in the switch by leveraging common header variations and optimized parsing techniques.
Implementation and Experimental Setup
NetShuffle's prototype leverages cutting-edge network hardware and software:
- Programmable Hardware Switch: The data plane is built on an Intel Tofino 1, a powerful programmable switch.
- Switch Controller: A regular CPU running Ubuntu manages the control plane logic, interacting with the Tofino switch.
- DNS Server: BIND9 running on a Google Cloud Platform (GCP) E2 medium instance (1 vCPU) handles hostname-to-external IP mappings.
- Epoch Configuration: For stress testing, the system was configured with two partitions and an epoch duration of 1 minute. The researchers note that in practice, longer durations (minutes or hours) would also be effective.
- Real-world Deployment: The system was deployed on a live campus network with a
/24IP subnet, handling approximately 2 TB of traffic per day.
Evaluation focused on the speed and stability of the shuffling mechanisms. The computation time for both the hosting-to-external IP and external-to-internal IP mapping tables was consistently sub-second. Updating the external-to-internal IP mapping table in the switch also occurred in sub-second durations. Even in the worst-case scenario of updating 10,000 unique subdomains per minute in the DNS server, the process took at most 1 second. These results confirm that NetShuffle's mapping updates are fast and stable, crucial for transparent operation.
Demo / Proof of Concept
▶ Watch: High-level overview of NetShuffle's operation (6:00)
To validate NetShuffle's real-world viability and transparency, the researchers conducted a practical demonstration using a live service hosted on their campus network: a LibreOffice mirror. This setup allowed them to evaluate NetShuffle's performance under realistic traffic conditions.
Two distinct tests were performed:
- Transfer Volume Comparison:
- This test compared the NetShuffle case (where client packets first passed through the NetShuffle switch before reaching the LibreOffice mirror) against a Baseline case (where packets were directly forwarded to the mirror).
- The experiments were conducted over multiple 2.5-hour windows at different periods to capture varying network loads.
- Result: The findings showed that the transfer volume and the number of clients served were approximately the same in both the NetShuffle and Baseline scenarios. This indicates that NetShuffle does not introduce significant bottlenecks or disrupt client connections, even with its dynamic shuffling mechanism.
- Client Vantage Point Transfer Rate:
- In this test, the researchers used their own vantage point to run a benchmark client that repeatedly accessed the LibreOffice mirror.
- Result: The transfer rate observed by the benchmark client was roughly similar whether NetShuffle was active or not. This further reinforced the conclusion that NetShuffle operates transparently from the client's perspective, without negatively impacting application performance.
Overall, the demonstration successfully proved that NetShuffle is capable of transparently serving large traffic volumes without degrading user experience or connection stability. The system's ability to maintain performance parity with a direct connection, while simultaneously providing robust circumvention capabilities through IP shuffling, underscores its practical utility. While the talk highlighted these key results, the presenters noted that more comprehensive evaluation details are available in the full paper.
Defensive Implications
▶ Watch: NetShuffle's epoch-based IP shuffling mechanism explained (7:00)
NetShuffle introduces significant defensive implications, primarily shifting the cost and complexity of censorship from the circumvention operator to the censor.
For nation-state censors, NetShuffle fundamentally alters the calculus of blocking:
- Increased Collateral Damage: The core mechanism of shuffling IP-to-service mappings means that an IP address identified as a "proxy" in one epoch might host a critical, legitimate service in the next. Consequently, blocking a single IP address that might be a proxy would risk blocking an entire Edge network's legitimate traffic, incurring substantial collateral damage. This makes fine-grained, IP-based blocking economically and politically unfeasible for censors who are sensitive to public and business disruption.
- Erosion of Fine-Grained Blocking: Censors' preferred strategy of targeting specific suspicious endpoints through enumeration attacks becomes much harder. Static blacklists of IP addresses are rendered ineffective within minutes (or hours, depending on epoch duration). Censors would need to develop highly sophisticated, real-time traffic analysis capabilities to identify proxy traffic amidst legitimate traffic, a task made challenging by the transparent nature of NetShuffle.
- Higher Detection Costs: To effectively block NetShuffle, censors would need to invest in advanced deep packet inspection and flow analysis systems capable of distinguishing circumvention traffic from legitimate traffic on a per-connection basis, potentially across dynamically changing IPs. This significantly raises the technical bar and operational cost for censorship.
- Difficulty in Enumeration: The dynamic nature of external IP addresses makes it difficult for censors to reliably enumerate and maintain a list of proxy endpoints. Any identified IP is ephemeral in its role as a proxy.
For circumvention users and operators, NetShuffle offers a more resilient and sustainable solution:
- New, Resilient Support Base: Edge networks provide a decentralized, high-collateral-damage support base that is less susceptible to political pressure than core networks and more robust against enumeration than end-user systems.
- Higher Unblockability: Users can expect a higher degree of unblockability due to the increased cost and difficulty for censors to block NetShuffle proxies.
- Transparent Operation: The system's transparency ensures that users do not experience degraded performance or require special client software, making circumvention more accessible.
- Scalability: The ability to leverage a large number of Edge networks (estimated 48,000 ASNs) provides a scalable approach to circumvention.
In essence, NetShuffle forces censors to either tolerate circumvention traffic or resort to highly disruptive, coarse-grained blocking measures that damage their own economy and legitimacy. This strategic shift in the economics of censorship is a powerful defensive implication.
Key Takeaways
- Edge networks are a powerful, underutilized support base: NetShuffle demonstrates that campus and enterprise networks offer an ideal middle ground for circumvention, providing both substantial collateral damage potential and a broad, decentralized support base (estimated 48,000 ASNs).
- Dynamic IP-to-service shuffling enhances unblockability: The core innovation of continuously changing external IP addresses for proxy services within an Edge network makes fine-grained blocking by censors prohibitively expensive due to the high risk of collateral damage.
- Asynchronous shuffling handles network complexities: NetShuffle's design effectively mitigates network propagation delays and DNS caching issues by maintaining outdated IP mappings for multiple epochs, ensuring robust and transparent client connections.
- Shuffle compaction optimizes IP utilization: Techniques like mapping multiple services to a single external IP (using different ports or SNI headers for disambiguation) address the challenge of limited IP addresses, making the system practical for real-world deployment.
- Programmable hardware enables efficient, transparent deployment: Leveraging an Intel Tofino 1 switch and a BIND9 DNS server, NetShuffle achieves sub-second mapping updates and transparently handles large traffic volumes (2 TB/day on a campus network) with a low resource footprint and minimal deployment effort.
- NetShuffle shifts the cost of censorship: By making fine-grained blocking impractical and forcing censors to incur significant collateral damage, NetShuffle fundamentally alters the economics of censorship, empowering individuals in censored regions with more reliable access to a free internet.
About the Speaker(s)
The primary presenter for "NetShuffle: Circumventing Censorship with Shuffle Proxies at the Edge" was Patrick Tser Jern Kon from the University of Michigan. He conducted this research as a joint work with his advisor, Ang Chen, also from the University of Michigan. The project involved a collaborative effort with additional researchers from different institutions, including Aniket Gattani, Dhiraj Saharia, Tianyu Cao, and Diogo Barradas. Their combined expertise in networking and security contributed to the development and evaluation of NetShuffle, an innovative system designed to combat global internet censorship.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This research introduces NetShuffle, a highly novel and robust system that re-architects censorship circumvention by leveraging Edge networks. Its dynamic IP-to-service shuffling mechanism effectively raises the cost of censorship for nation-states, making fine-grained blocking economically unfeasible. The technical solutions for network asynchrony and IP compaction, deployed on programmable hardware, demonstrate real ingenuity and practical viability.
Heather Calloway (CISO) — STRONG ACCEPT
NetShuffle presents a compelling, practical system that fundamentally alters the economics of nation-state censorship by leveraging edge networks and dynamic IP shuffling. It effectively transfers the cost and risk of blocking from circumvention efforts to the censors, making fine-grained blocking economically unfeasible. This research offers a clear, actionable path for institutions to support global information freedom.
→ Top-rated talks at IEEE Symposium on Security and Privacy 2024