Explicit QUIC Proxies for Server-Side Geo-blocking Bypass

📅 2026-10-05
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the high cost and latency limitations of traditional VPN-based server-side geo-blocking circumvention by proposing a low-overhead, low-latency approach that exploits the connection migration feature of the QUIC protocol. The core innovation is a "post-header migration" mechanism that shifts data transmission to an unauthorized IP path after the initial request passes geo-verification, thereby overcoming the constraint of relying solely on post-handshake migration. The system employs an HTTP/2-to-HTTP/3 proxy architecture to facilitate path migration and blocking detection. Experimental results demonstrate that 99% of the data is transmitted via unauthorized paths, with at least 75% of the data volume migrated for targets supporting QUIC migration, successfully circumventing geo-blocking across 90% of the evaluated target domains.
📝 Abstract
Geo-restricted content is increasingly common on the Internet, forcing users to rely on circumvention techniques, such as VPNs, to access the web from a seemingly different location. However, these often come with a financial cost and can degrade performance. The rise in popularity of the QUIC protocol, which allows connections to migrate between paths, opens opportunities to circumvent such restrictions. We scan web servers and find that a large portion of geo- blocked content is enforced on the server, at the application layer, rather than on-path. This check is performed once, when the request arrives, and is not repeated as the connection continues. This allows a client to issue its request from a whitelisted IP address and, once the server has accepted it, migrate the connection to an otherwise unauthorized address for the rest of the transfer (post-header migration). It bypasses the block while maximizing direct traffic, thereby reducing eventual circumvention-related costs. Building on this insight, we introduce Stork, an HTTP/2-to-HTTP/3 web proxy that bypasses geo-blocking while introducing negligible additional latency. We demonstrate that our solution is compatible with popular clients and servers. In controlled experiments with 2 MB requests, our proxy migrates 99% of the transferred data onto the unauthorized path. Across real-world targets that support QUIC migration, it migrates at least 75% of the data for more than 52% of them. On real geo-blocked content, post-header migration bypasses the block for 90% of domains, whereas post-handshake migration, as used by prior work, succeeds for only 60%.
Problem

Research questions and friction points this paper is trying to address.

Geo-blocking
QUIC
Connection Migration
Circumvention
Web Proxy
Innovation

Methods, ideas, or system contributions that make the work stand out.

QUIC connection migration
geo-blocking bypass
post-header migration
HTTP/2-to-HTTP/3 proxy
Stork
🔎 Similar Papers
No similar papers found.