FINDING · DETECTION

Cross-layer RTT discrepancy (RTTdiff) is a protocol-agnostic fingerprint that exploits an inherent architectural property of all proxy setups: transport-layer sessions terminate at the proxy while application-layer sessions remain end-to-end. Evaluation across 10 proxy protocols—including VMess, Shadowsocks, VLESS, Trojan, XTLS-Vision, and obfs4-wrapped SOCKS—shows near-identical detection rates for all except obfs4, confirming the fingerprint is not tied to any specific obfuscation scheme. At FPR=0.01, per-website detection rates exceed 70% across all tested client and proxy location combinations.

From 2025-xue-discriminativeThe Discriminative Power of Cross-layer RTTs in Fingerprinting Proxy Traffic · §I, §VI-C · 2025 · Network and Distributed System Security

Implications

Tags

censors
genericcnru
techniques
traffic-shapeflow-correlation
defenses
shadowsocksvmessvlesstrojanobfs4pluggable-transport

Extracted by claude-sonnet-4-6 — review before relying.