Waterfall's Overt User Simulator caches previously loaded overt-website responses and replays them to generate cover traffic, overcoming Slitheen's 40% downstream throughput ceiling (caused by restricting covert replacement to leaf HTTP objects only). Because downstream-only decoy routers intercept all downstream TLS records — not just leaf content — Waterfall achieves higher covert capacity while perfectly mimicking overt browsing patterns against traffic analysis.
From 2017-nasr-waterfall — The Waterfall of Liberty: Decoy Routing Circumvention that Resists Routing Attacks
· §9
· 2017
· Computer and Communications Security
Implications
Use response-caching headless browsers (Selenium/PhantomJS pattern) to generate cover traffic rather than live leaf-content replacement; this removes the 40% throughput cap while preserving packet-size and timing patterns against statistical classifiers.
Avoid TLS heartbeat messages as a primary upstream covert channel in overt-mimicking systems — their rarity in normal connections makes them a high-salience anomaly under deep packet inspection.