FINDING · EVALUATION

High-fidelity statistical mimicry of Amazon.com traffic — simultaneously matching HTTP response payload length distributions, request-response pairs per TCP connection, and simultaneously active connection counts — reduced goodput to 0.45 Mbps downstream and 0.32 Mbps upstream, versus 6.6/6.7 Mbps for simple RFC-compliant FTP mimicry. The bottleneck was the prevalence of very short payloads (most common length: 43 bytes) forcing frequent TCP connection setup and teardown, with the server blocked on network I/O 98.8% of the time.

From 2015-dyer-marionetteMarionette: A Programmable Network-Traffic Obfuscation System · §7.4, §7.6 · 2015 · USENIX Security Symposium

Implications

Tags

techniques
traffic-shape
defenses
marionette

Extracted by claude-sonnet-4-6 — review before relying.