FINDING · DEFENSE
Waterfall's Overt User Simulator caches previously loaded overt-website responses and replays them to generate cover traffic, overcoming Slitheen's 40% downstream throughput ceiling (caused by restricting covert replacement to leaf HTTP objects only). Because downstream-only decoy routers intercept all downstream TLS records — not just leaf content — Waterfall achieves higher covert capacity while perfectly mimicking overt browsing patterns against traffic analysis.
From 2017-nasr-waterfall — The Waterfall of Liberty: Decoy Routing Circumvention that Resists Routing Attacks · §9 · 2017 · Computer and Communications Security
Implications
- Use response-caching headless browsers (Selenium/PhantomJS pattern) to generate cover traffic rather than live leaf-content replacement; this removes the 40% throughput cap while preserving packet-size and timing patterns against statistical classifiers.
- Avoid TLS heartbeat messages as a primary upstream covert channel in overt-mimicking systems — their rarity in normal connections makes them a high-salience anomaly under deep packet inspection.
Tags
Extracted by claude-sonnet-4-6 — review before relying.