FINDING · DETECTION

While stream multiplexing reduces the visibility of encapsulated TLS handshakes by merging inner connections, the paper cautions that multiplexing plus random padding alone is "inherently limited" as a long-term countermeasure. Censors can adapt by monitoring burst sizes and round-trip counts at the outer-connection level, which remain correlated with the number of inner TLS sessions regardless of padding.

From 2024-xue-fingerprintingFingerprinting Obfuscated Proxy Traffic with Encapsulated TLS Handshakes · §7 (Limitations and Future Work) · 2024 · USENIX Security Symposium

Implications

Tags

censors
generic
techniques
dpitls-fingerprinttraffic-shape
defenses
vmessvlessreality

Extracted by claude-sonnet-4-6 — review before relying.