The Discriminative Power of Cross-layer RTTs in Fingerprinting Proxy Traffic
Diwen Xue, Robert Stanley, Piyush Kumar, Roya Ensafi
Abstract
—The escalating global trend of Internet censorship has necessitated an increased adoption of proxy tools, especially obfuscated circumvention proxies. These proxies serve a fundamental need for access and connectivity among millions in heavily censored regions. However, as the use of proxies expands, so do censors’ dedicated efforts to detect and disrupt such circumvention traffic to enforce their information control policies. In this paper, we bring out the presence of an inherent fingerprint for detecting obfuscated proxy traffic. The fingerprint is created by the misalignment of transport-and application-layer sessions in proxy routing, which is reflected in the discrepancy in Round Trip Times (RTTs) across network layers. Importantly, being protocol-agnostic, the fingerprint enables an adversary to effectively target multiple proxy protocols simultaneously. We conduct an extensive evaluation using both controlled testbeds and real-world traffic, collected from a partner ISP, to assess the fingerprint’s potential for exploitation by censors. In addition to being of interest on its own, our timing-based fingerprinting vulnerability highlights the deficiencies in existing obfuscation approaches. We hope our study brings the attention of the circum-vention community to packet timing as an area of concern and leads to the development of more sustainable countermeasures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c7be48eb-8f71-4365-9e96-2f25d4fad67fCited by top-tier papers4
- MVPNalyzer: An Investigative Framework for Auditing the Security & Privacy of Mobile VPNsWayne Wang, Aaron Ortwein, Enrique Sobrados, Robert Stanley et al.NDSS 2026 · 2 citations
- Beyond RTT: An Adversarially Robust Two-Tiered Approach For Residential Proxy DetectionTemoor Ali, Shehel Yoosuf, Mouna Rabhi, Mashael Al Sabah et al.NDSS 2026 · 1 citation
- Fingerprinting Deep Packet Inspection Devices by their AmbiguitiesDiwen Xue, Armin Huremagic, Wayne Wang, Ram Sundara Raman et al.CCS 2025
- Evaluating Practical Enumeration and Blocking Attacks on the Snowflake Circumvention SystemLinden Chen, Ryan Sangha, Cecylia Bocovich, Ram Sundara RamanCCS 2026
Builds on16
- DeepCorr: Strong Flow Correlation Attacks on Tor Using Deep LearningMilad Nasr, Alireza Bahramali, Amir HoumansadrCCS 2018 · 187 citations
- TrafficSliver: Fighting Website Fingerprinting Attacks with Traffic SplittingWladimir De la Cadena, Asya Mitseva, Jens Hiller, Jan Pennekamp et al.CCS 2020 · 110 citations
- The use of TLS in Censorship CircumventionSergey Frolov, Eric WustrowNDSS 2019 · 97 citations
- SoK: Towards Grounding Censorship Circumvention in EmpiricismMichael Carl Tschantz, Sadia Afroz, anonymous, Vern PaxsonS&P 2016 · 89 citations
- Augur: Internet-Wide Detection of Connectivity DisruptionsPaul Pearce, Roya Ensafi, Frank Li, Nick Feamster et al.S&P 2017 · 84 citations
Related papers
- Fingerprinting Obfuscated Proxy Traffic with Encapsulated TLS HandshakesDiwen Xue, Michalis Kallitsis, Amir Houmansadr, Roya EnsafiUSENIX Security 2024 · 24 citations
- OpenVPN is Open to VPN FingerprintingDiwen Xue, Reethika Ramesh, Arham Jain, Michalis Kallitsis et al.USENIX Security 2022
- Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-LayerNiklas Niere, Felix Lange, Robert Merget, Juraj SomorovskyS&P 2025
- Slitheen: Perfectly Imitated Decoy Routing through Traffic ReplacementCecylia Bocovich, Ian GoldbergCCS 2016 · 40 citations
- Detecting Probe-resistant ProxiesSergey Frolov, Jack Wampler, Eric WustrowNDSS 2020
