The Discriminative Power of Cross-layer RTTs in Fingerprinting Proxy Traffic
Diwen Xue, Robert Stanley, Piyush Kumar, Roya Ensafi
摘要
—The escalating global trend of Internet censorship has necessitated an increased adoption of proxy tools, especially obfuscated circumvention proxies. These proxies serve a fundamental need for access and connectivity among millions in heavily censored regions. However, as the use of proxies expands, so do censors’ dedicated efforts to detect and disrupt such circumvention traffic to enforce their information control policies. In this paper, we bring out the presence of an inherent fingerprint for detecting obfuscated proxy traffic. The fingerprint is created by the misalignment of transport-and application-layer sessions in proxy routing, which is reflected in the discrepancy in Round Trip Times (RTTs) across network layers. Importantly, being protocol-agnostic, the fingerprint enables an adversary to effectively target multiple proxy protocols simultaneously. We conduct an extensive evaluation using both controlled testbeds and real-world traffic, collected from a partner ISP, to assess the fingerprint’s potential for exploitation by censors. In addition to being of interest on its own, our timing-based fingerprinting vulnerability highlights the deficiencies in existing obfuscation approaches. We hope our study brings the attention of the circum-vention community to packet timing as an area of concern and leads to the development of more sustainable countermeasures.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- MVPNalyzer: An Investigative Framework for Auditing the Security & Privacy of Mobile VPNsWayne Wang, Aaron Ortwein, Enrique Sobrados, Robert Stanley 等NDSS 2026 · 被引用 2 次
- Beyond RTT: An Adversarially Robust Two-Tiered Approach For Residential Proxy DetectionTemoor Ali, Shehel Yoosuf, Mouna Rabhi, Mashael Al Sabah 等NDSS 2026 · 被引用 1 次
- Fingerprinting Deep Packet Inspection Devices by their AmbiguitiesDiwen Xue, Armin Huremagic, Wayne Wang, Ram Sundara Raman 等CCS 2025
- Evaluating Practical Enumeration and Blocking Attacks on the Snowflake Circumvention SystemLinden Chen, Ryan Sangha, Cecylia Bocovich, Ram Sundara RamanCCS 2026
它引用的顶会 Paper16
- DeepCorr: Strong Flow Correlation Attacks on Tor Using Deep LearningMilad Nasr, Alireza Bahramali, Amir HoumansadrCCS 2018 · 被引用 187 次
- TrafficSliver: Fighting Website Fingerprinting Attacks with Traffic SplittingWladimir De la Cadena, Asya Mitseva, Jens Hiller, Jan Pennekamp 等CCS 2020 · 被引用 110 次
- The use of TLS in Censorship CircumventionSergey Frolov, Eric WustrowNDSS 2019 · 被引用 97 次
- SoK: Towards Grounding Censorship Circumvention in EmpiricismMichael Carl Tschantz, Sadia Afroz, anonymous, Vern PaxsonS&P 2016 · 被引用 89 次
- Augur: Internet-Wide Detection of Connectivity DisruptionsPaul Pearce, Roya Ensafi, Frank Li, Nick Feamster 等S&P 2017 · 被引用 84 次
相关 Paper
- Fingerprinting Obfuscated Proxy Traffic with Encapsulated TLS HandshakesDiwen Xue, Michalis Kallitsis, Amir Houmansadr, Roya EnsafiUSENIX Security 2024 · 被引用 24 次
- OpenVPN is Open to VPN FingerprintingDiwen Xue, Reethika Ramesh, Arham Jain, Michalis Kallitsis 等USENIX Security 2022
- Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-LayerNiklas Niere, Felix Lange, Robert Merget, Juraj SomorovskyS&P 2025
- Slitheen: Perfectly Imitated Decoy Routing through Traffic ReplacementCecylia Bocovich, Ian GoldbergCCS 2016 · 被引用 40 次
- Detecting Probe-resistant ProxiesSergey Frolov, Jack Wampler, Eric WustrowNDSS 2020
