FINDING · DETECTION
Censors employing deep learning can use DTLS connection duration as a precise identifier to classify and block Snowflake traffic. The paper proposes switching PT connections after a variable time limit as a countermeasure to prevent duration-based classification.
From 2024-lorimer-extended — Extended Abstract: Traffic Splitting for Pluggable Transports · §4.3 · 2024 · Free and Open Communications on the Internet
Implications
- Randomize DTLS/WebRTC session lifetimes with a variable timeout rather than fixed keepalives to disrupt duration-based deep-learning classifiers.
- Proactively migrate connections before reaching any predictable duration threshold, treating connection age as a fingerprintable feature on par with packet sizes.
Tags
Extracted by claude-sonnet-4-6 — review before relying.