There are some things related to the size and timing of packets that you can use to infer the likeliness of a given handshake inside the TLS stream. The great firewall does similar things to detect Tor. (Not related to the IP-over-HTTP presented above however.)