From what I understand, Shadowsocks masks SOCKS5 traffic as HTTPS traffic, so that the GFW cannot detect it by packet inspection. Shadowsocks can be installed on my own server, naturally. For usage, I would establish a connection with a Shadowsocks client and point my browser's SOCKS5 configuration to a certain port on localhost. Now, all my traffic when browsing the web is exchanged between my PC and my server, via my ISP. And here I don't understand:
Doesn't it look suspicious to the GFW if an individual's daily Internet traffic is happening between his PC and just one server? Wouldn't it be trivial for the GFW to eliminate Shadowsocks connections by blocking IPs?