FINDING · DETECTION

Per-flow RTTdiff detection rates are only ~20% because the majority of proxy flows connect to CDN-cached content (Cloudflare, Google, Fastly) that sits within 5ms of the proxy, suppressing the discrepancy. However, aggregating across flows per website visit yields detection rates exceeding 70%—and from the abstract, approximately 80% of top-5K domains generate at least one detectable flow—with half of those detections made within the first 60 packets. This means an adversary can reliably expose client and proxy IPs after just a few website visits.

From 2025-xue-discriminativeThe Discriminative Power of Cross-layer RTTs in Fingerprinting Proxy Traffic · §VI-C-2, Table II · 2025 · Network and Distributed System Security

Implications

Tags

censors
generic
techniques
traffic-shapeflow-correlation
defenses
shadowsocksvlessvmesstrojan

Extracted by claude-sonnet-4-6 — review before relying.