I don't understand why timings are critical to the operation of the system. Wouldn't packet filtering + transparent proxying work just as effectively? Is this a TCP sequencing attack of some kind?
[1] https://www.documentcloud.org/documents/785152-166819124-mit...