With the increase in Internet censorship globally, various circumvention tools have been designed and developed. However, the monetary cost of these tools deeply impacts both user choice and the sustainability of provider operations. Recent developments in censorship circumvention research attempted to achieve cost efficiency by utilizing Infrastructure-as-a-Service (IaaS) spot instances as bridges, but still incurred substantial expenses related to network connectivity and instance maintenance. In this work, we present CensorLess, a circumvention proxy built leveraging the unique benefits of a serverless platform. CensorLess comprises three components: a local proxy that handles client-side communication and ensures compliance with serverless functions' security restrictions, a function refresher that periodically regenerates bridges, and a live migration mechanism that maintains continuous connectivity. CensorLess inherits the serverless platform's cost efficiency, ephemerality, scalability, concurrency, and performance. Compared to existing low-cost, state-of-the-art circumvention techniques, CensorLess reduces costs by 97%, while simultaneously enabling robust censorship resistance by employing bridge rotation.
翻译:随着全球互联网审查的加剧,各种规避工具被设计和开发出来。然而,这些工具的货币成本深刻影响着用户的选择以及服务提供商运营的可持续性。近期审查规避研究的发展试图通过利用基础设施即服务(IaaS)竞价实例作为桥接节点来实现成本效益,但仍产生了与网络连接和实例维护相关的可观费用。在本工作中,我们提出了CensorLess,这是一个利用无服务器平台独特优势构建的规避代理。CensorLess包含三个组件:一个处理客户端通信并确保符合无服务器函数安全限制的本地代理、一个定期再生桥接节点的函数刷新器,以及一个维持持续连接的实时迁移机制。CensorLess继承了无服务器平台的成本效益、临时性、可扩展性、并发性和性能。与现有的低成本、最先进的规避技术相比,CensorLess将成本降低了97%,同时通过采用桥接节点轮换实现了强大的抗审查能力。