The Discriminative Power of Cross-layer RTTs in Fingerprinting Proxy Traffic

Diwen Xue (University of Michigan)

Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · Network Security 1

Overview

In an era of increasing internet censorship, geoblocking, and network interference, users frequently rely on encrypted tunnels and proxy servers to circumvent restrictions. This talk, "The Discriminative Power of Cross-layer RTTs in Fingerprinting Proxy Traffic," presented by Diwen Xue from the University of Michigan, delves into a novel and potent method for detecting such circumvention tools. Rather than targeting the specific obfuscation techniques employed by individual proxy protocols, this research introduces a protocol-agnostic fingerprint that exploits a fundamental property shared by all tunneling solutions: the misalignment of network sessions across different layers.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction: The arms race against censorship and firewalls
  2. 2:30 Novel approach: Protocol-agnostic tunnel fingerprinting
  3. 3:30 Core mechanism: RTT mismatch from cross-layer session misalignment
  4. 4:45 Concrete example: Tunneling adds significant RTT discrepancy
  5. 5:45 Measuring application layer RTT with cross-correlation
  6. 6:20 Statistical detection: Differentiating proxy routing from server delay
  7. 7:30 Practical results: High detection of obfuscated proxies

The Discriminative Power of Cross-layer RTTs in Fingerprinting Proxy Traffic

Speakers: Diwen Xue, University of Michigan

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=i_yBhIYsMBw

Overview

In an era of increasing internet censorship, geoblocking, and network interference, users frequently rely on encrypted tunnels and proxy servers to circumvent restrictions. This talk, "The Discriminative Power of Cross-layer RTTs in Fingerprinting Proxy Traffic," presented by Diwen Xue from the University of Michigan, delves into a novel and potent method for detecting such circumvention tools. Rather than targeting the specific obfuscation techniques employed by individual proxy protocols, this research introduces a protocol-agnostic fingerprint that exploits a fundamental property shared by all tunneling solutions: the misalignment of network sessions across different layers.

The core insight is that while application layer traffic remains end-to-end from client to destination server, the transport layer connection terminates at the proxy. This architectural difference introduces a measurable discrepancy in Round-Trip Times (RTTs) between the transport and application layers. Xue demonstrates how this cross-layer RTT discrepancy can serve as a robust signal for the presence of a tunnel, even when faced with state-of-the-art obfuscation. The findings presented are highly significant, not only advancing the capabilities of network censors and firewalls but also highlighting critical limitations in current circumvention strategies, thereby intensifying the ongoing arms race in network freedom.

Background

▶ Watch: Introduction: The arms race against censorship and firewalls (0:00)

The internet's architecture, originally designed for open communication, is increasingly shaped by various forms of interference, including state-sponsored censorship, corporate geoblocking, and server-side filtering. To bypass these restrictions, users commonly employ circumvention tools that encapsulate their traffic within encrypted tunnels, routing it through a proxy server located outside the controlled network. These tunnels encrypt the internal traffic, preventing firewalls and middleboxes from inspecting the content and triggering blocks.

However, firewalls are not static entities; they actively seek to identify and block the tunneling protocols themselves. This has led to a protracted arms race spanning over two decades. On one side, proxy systems like Shadowsocks, Trojan, and V2Ray employ sophisticated obfuscation techniques to disguise their traffic, making it appear as legitimate, unencrypted traffic or mimicking common protocols like TLS. On the other side, censors and firewalls continuously evolve their detection methods to unmask these obfuscations and shut down circumvention efforts.

Previous fingerprinting research and deployed detection mechanisms have predominantly focused on identifying specific flaws or unique signatures within individual obfuscation protocols. For instance, the Snowflake circumvention tool was once detected due to subtle differences in its TLS handshake compared to mainstream browsers. Such protocol-specific detection methods, however, are often short-lived. As soon as a flaw is identified, developers of circumvention tools can patch it or introduce new obfuscations, effectively playing a game of "whack-a-mole" with censors. This approach often assumes that resource-limited firewalls cannot keep pace with the rapid proliferation of new obfuscation variants. This research challenges that assumption by proposing a detection mechanism that transcends individual protocol specifics, targeting a more fundamental characteristic of tunneling itself.

Key Findings

▶ Watch: Core mechanism: RTT mismatch from cross-layer session misalignment (3:30)

The central discovery presented in this work is that any form of network tunneling inherently introduces a measurable and exploitable discrepancy in Round-Trip Times (RTTs) across different network layers. This cross-layer RTT discrepancy provides a powerful, protocol-agnostic fingerprint for detecting proxy traffic, regardless of the specific obfuscation techniques employed.

The core observation is that in a tunneled connection, the transport layer (e.g., TCP) session terminates at the proxy server, while the application layer (e.g., HTTP/S) session conceptually remains end-to-end, directly from the client to the final web server. This architectural divergence means that the network paths traversed by transport-layer acknowledgements (between client and proxy) and application-layer responses (between client, proxy, and web server) are significantly different, leading to a measurable mismatch in their respective RTTs.

Through extensive testing against popular obfuscated proxies, including Shadowsocks, V2Ray, and OPAQUE 4, the researchers demonstrated the high efficacy of this fingerprint. When evaluating detection rates at the flow level, the method showed moderate effectiveness. However, when aggregating detection by website visits (which typically involve multiple individual flows), the detection rates soared to over 70%. This implies that a firewall could reliably flag the use of a tunnel after just two or three visits to different domains. The study found that most missed detections at the flow level were attributed to third-party requests to Content Delivery Networks (CDNs) or trackers, often served within extremely short latencies (e.g., 5 milliseconds) from the proxy's location, resulting in minimal RTT discrepancies.

Crucially, the research also evaluated the false positive rate by applying the fingerprint to real user traffic measured from a backbone router of a regional ISP. The estimated false positive rate was remarkably low, approximately 0.6%. This figure is comparable to the false positive rates reportedly achieved by real-world censorship systems, underscoring the practical viability and specificity of this detection method. The findings indicate that the cross-layer RTT discrepancy is a robust and reliable indicator of proxy traffic, presenting a significant advancement in the capabilities of network monitoring and censorship.

Technical Deep Dive

▶ Watch: Concrete example: Tunneling adds significant RTT discrepancy (4:45)

The technical foundation of this fingerprint lies in the inherent architectural differences between direct and tunneled network connections, specifically how sessions terminate across different network layers.

In a direct HTTPS connection, the client establishes a single transport-layer (TCP) connection directly with the web server. After the TCP handshake, the client sends a Client Hello (application layer) and receives a transport-layer acknowledgement (ACK) from the server. Subsequently, the client receives the Server Hello (application layer). The difference between the transport-layer RTT (time to receive ACK) and the application-layer RTT (time to receive Server Hello) is primarily the processing delay at the web server.

In contrast, with a tunneled connection, the scenario is more complex due to the proxy's intermediary role. The client establishes a transport-layer connection with the proxy server, not the final web server. When the client sends its request (e.g., Client Hello encapsulated within the tunnel), the proxy immediately acknowledges receipt at the transport layer. However, the proxy then needs to establish its own separate transport-layer connection to the final web server, perform its handshake, relay the client's encapsulated request, wait for the web server's response, and then forward that response back to the client.

This multi-hop process fundamentally alters the cross-layer RTT relationship. As Diwen Xue explains, the RTT difference across layers for the tunneling case is not merely the processing delay at the web server. Instead, "it also includes up to three times the propagation delay from the proxy to the web server" (04:47). This significant amplification of the delay component between the transport-layer ACK and the application-layer response forms the basis of the fingerprint.

To exploit this, firewalls must be able to observe this RTT difference. Measuring the transport-layer RTT is relatively straightforward, as it involves monitoring TCP acknowledgements. However, determining the application-layer RTT within an encrypted tunnel presents a significant challenge. Since the tunnel encrypts all application data, a firewall cannot simply inspect packet headers to match requests with responses. A naive approach of assuming the next incoming packet is a response to the most recent outgoing one can be easily misled by out-of-order delivery, multiplexing, or multiple concurrent requests.

To overcome this, the research proposes a cross-correlation-based approach (05:40). The key idea is to measure the similarity between the pattern of outgoing requests and the pattern of incoming responses as a function of various potential delays. By shifting the response pattern relative to the request pattern and calculating the correlation, the delay that yields the strongest alignment is identified as the most probable application-layer RTT. This statistical method allows the firewall to infer the application-layer RTT even without decrypting the tunnel content.

Once the cross-layer RTT difference is observed, the next step is to decide whether this difference is indicative of normal server processing delay or an added propagation delay due to proxy routing. This is framed as a statistical detection problem using sequential hypothesis testing (06:15). Two hypotheses are considered:

  1. The connection is direct.
  2. What appears to be a transport-layer server is actually a proxy.

For each connection, multiple estimates for the RTT differences are accumulated, and a statistical model determines which hypothesis is more likely. The research visually illustrates this, showing that the cross-layer RTT discrepancy for direct connections (represented by a red curve) is typically much smaller than for proxy traffic (represented by a green curve). The proxy routing consistently adds propagation delay that far exceeds what a typical server processing time could explain, creating a distinct and exploitable "shaded area" of difference (06:40). This robust statistical differentiation underpins the high detection specificity observed in the study.

Demo / Proof of Concept

▶ Watch: Statistical detection: Differentiating proxy routing from server delay (6:20)

The "Demo / Proof of Concept" for this research was conducted through a rigorous evaluation of the proposed fingerprinting method against a variety of real-world scenarios and popular circumvention tools, rather than a live, interactive demonstration. The methodology involved setting up a controlled environment to simulate real-world proxy usage and then deploying the detection mechanism to assess its effectiveness.

The researchers tested the fingerprint against several widely used and state-of-the-art obfuscated proxy protocols, including:

  • Shadowsocks
  • V2Ray
  • OPAQUE 4 (a protocol specifically designed to obfuscate timing patterns)

These tools were chosen because their primary objective is to avoid detection as tunnels, making them ideal candidates for stress-testing the new fingerprint. The experimental setup involved establishing client and proxy servers across different continents to simulate realistic network latencies and routing complexities. Clients then visited top-ranked domains, generating diverse traffic patterns for analysis.

The evaluation specifically focused on two key metrics:

  1. Detection rates: Measured both at the individual flow level and aggregated by website visits. The aggregated detection rate exceeding 70% for website visits (08:00) highlights the practical utility for a firewall.
  2. False positive rate: To assess the real-world applicability and avoid collateral damage, the fingerprint was applied to actual user traffic. This was achieved by collaborating with a regional ISP and analyzing data collected from a backbone router. The estimated false positive rate of approximately 0.6% (08:30) is a critical validation, demonstrating that the method is highly specific and unlikely to flag legitimate traffic incorrectly. This low rate is comparable to those reported by existing real-world censorship systems, suggesting the fingerprint's readiness for practical deployment.

Furthermore, the study investigated various factors that could influence the sensitivity of the fingerprint, such as DNS resolution and routing configurations. These factors were found to potentially amplify the cross-layer RTT discrepancy, further enhancing the detection capabilities. This comprehensive evaluation serves as the proof of concept, demonstrating that the cross-layer RTT fingerprint is not only theoretically sound but also highly effective and practical in identifying obfuscated proxy traffic under realistic conditions.

Defensive Implications

▶ Watch: Practical results: High detection of obfuscated proxies (7:30)

The findings of this research carry significant implications for both network defenders (e.g., firewalls, censors) and developers of circumvention tools.

For network defenders, this work provides a potent, protocol-agnostic weapon in the ongoing arms race against circumvention. Unlike previous fingerprinting methods that targeted specific obfuscation techniques, this approach exploits a fundamental architectural property shared by all tunneling solutions. This makes it far more resilient to protocol updates and new obfuscation variants. The demonstrated practicality, including high detection rates (over 70% for aggregated website visits) and a low false positive rate (0.6% on real-world ISP traffic), suggests that this fingerprint could be a valuable addition to a censor's toolkit. However, Diwen Xue acknowledges that the fingerprint "heavily relies on subtle timing patterns which can be affected by the changing network conditions" (09:00), implying that its effectiveness might vary depending on network stability and congestion. Despite this, its potential for widespread deployment is undeniable given its robustness against current obfuscation strategies.

For developers of circumvention tools, this research highlights a critical vulnerability and the limitations of many existing obfuscation techniques. The talk specifically details the failure of OPAQUE 4, a protocol designed to obfuscate timing, to evade this fingerprint. Surprisingly, adding OPAQUE 4 not only lowered performance but also "increases the exposure to the fingerprint" (10:00). This counterintuitive result stems from OPAQUE 4's design: it only applies random delays when there is actual application data in the sending buffer. If the application is idle or data is in transit, OPAQUE 4 does nothing, leaving the underlying RTT difference exposed or even exacerbated.

This points to a broader issue: many current obfuscation strategies are "application-dependent." They primarily focus on inflating packet sizes or adding delays when data actively moves from the application layer to the obfuscation layer. Such methods are fundamentally unable to hide patterns that are inherently involved with larger sizes or longer RTTs than what is considered normal in a given context. The cross-layer RTT fingerprint is a clear example of such a pattern. This limitation was also observed in the speaker's previous work on padded sizes, suggesting a systemic weakness in current obfuscation paradigms.

To counter this new fingerprint, circumvention tools would need to implement more sophisticated countermeasures. The paper evaluated a few options, such as traffic multiplexing, splitting, or deliberately delaying the transmission of ACK packets at the proxy to obscure the RTT gap (09:40). However, the fundamental challenge remains: how to "blend in" with normal, direct internet traffic without making it obvious that something special is being done. As Xue aptly points out, "What is a normal timing distribution look like on the internet? What is a background traffic on the internet? Like to answer that question even like it's just a it's a like it's a it's a research question just I don't I don't think it's been resolved yet" (13:50). This indicates that effective countermeasures would likely require a deep understanding and emulation of legitimate network traffic patterns, a significantly harder problem than simply adding random delays or padding. The arms race is thus propelled to a new level of complexity, demanding more flexible and resilient obfuscation architectures.

Key Takeaways

  • Cross-layer RTT Discrepancy: A fundamental architectural property of all tunneling solutions leads to a measurable mismatch between transport-layer and application-layer Round-Trip Times (RTTs).
  • Protocol-Agnostic Fingerprint: This RTT discrepancy provides a robust, protocol-agnostic method for detecting proxy traffic, making it resilient to specific obfuscation techniques like those in Shadowsocks, V2Ray, or OPAQUE 4.
  • High Detection Rates & Low False Positives: The fingerprint achieved over 70% detection for aggregated website visits and a low 0.6% false positive rate on real-world ISP traffic, demonstrating its practical viability for network censors.
  • Limitations of Current Obfuscation: Many current obfuscation tools, including OPAQUE 4, are "application-dependent" and fail to hide inherent timing patterns like the cross-layer RTT discrepancy, potentially even increasing exposure.
  • New Arms Race Dynamic: The research escalates the arms race, shifting the focus from detecting specific obfuscations to identifying fundamental characteristics of tunneling, requiring circumvention tools to develop more sophisticated, context-aware countermeasures that can genuinely "blend in" with normal internet traffic.
  • Complex Countermeasure Challenge: Developing effective countermeasures will require solving the difficult research problem of understanding and mimicking "normal" internet timing distributions, going beyond simple padding or random delays.

About the Speaker(s)

Diwen Xue is a researcher from the University of Michigan. His work, as presented in this talk and referenced previous work, focuses on the ongoing arms race between circumvention tools and network censorship, particularly exploring novel methods for fingerprinting obfuscated traffic and identifying limitations in existing obfuscation techniques. His research aims to understand and improve the resilience of circumvention against detection.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Xue brings a genuinely novel, protocol-agnostic fingerprinting primitive to a space that has been stuck in whack-a-mole mode for years. The cross-layer RTT discrepancy insight is architecturally fundamental — it doesn't care what obfuscation layer you bolt on top — and the 0.6% FPR on live ISP backbone traffic is the kind of real-world validation that separates academic papers from deployable threat models. The counterintuitive OPAQUE 4 result alone is worth the admission.

Heather Calloway (CISO) — WEAK

Technically rigorous work on a real and underappreciated detection vector, but the talk is aimed at researchers, not operators or decision-makers. The findings have genuine implications for privacy tool developers and network defenders, but neither group leaves with a clear action path.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025