FINDING · DEFENSE

Slitheen++ embeds covert upstream data by applying HTTP/2-like header field compression to overt HTTP requests, using the recovered space for covert data placement. This ensures that neither timing information nor observable changes to packet sizes or delays can reveal decoy routing use to an omni-scientist passive censor. GZIP compression was explicitly avoided to prevent the CRIME side-channel attack.

From 2020-birtel-slitheenSlitheen++: Stealth TLS-based Decoy Routing · §4 · 2020 · Free and Open Communications on the Internet

Implications

Tags

censors
generic
techniques
traffic-shapedpi
defenses
decoy-routingmimicry

Extracted by claude-sonnet-4-6 — review before relying.