FINDING · DETECTION

IMAP/SSL traffic on port 993 constitutes less than 1% of total ISP traffic but accounts for nearly one third of all false positives in the RTTdiff exploit, because IMAP's non-RESTful multi-connection pattern violates the request-response correlation assumption. The overall per-flow FPR is bounded at 0.6–0.7% (on par with GFW's estimated FPR against fully-encrypted proxies), but implementing a pre-filter to whitelist IMAP traffic reduces the FPR by approximately one third, making the fingerprint substantially more precise.

From 2025-xue-discriminativeThe Discriminative Power of Cross-layer RTTs in Fingerprinting Proxy Traffic · §VI-C-3, Table III · 2025 · Network and Distributed System Security

Implications

Tags

censors
genericcn
techniques
traffic-shapeflow-correlation

Extracted by claude-sonnet-4-6 — review before relying.