FINDING · DETECTION

A censor can identify Slitheen relay connections by observing that all packets in a suspected overt flow arrive in strict order while flows from the same source naturally exhibit out-of-order delivery: the relay station's traffic-server component reorders TCP segments to enable TLS record decryption, creating a statistically anomalous per-connection ordering pattern. The reordering buffer also increases per-packet round-trip times, providing a secondary timing signal.

From 2020-birtel-slitheenSlitheen++: Stealth TLS-based Decoy Routing · §4, §6 · 2020 · Free and Open Communications on the Internet

Implications

Tags

censors
generic
techniques
traffic-shapemiddlebox-interferenceflow-correlation
defenses
decoy-routing

Extracted by claude-sonnet-4-6 — review before relying.