FINDING · DEFENSE

GFW-injected RST packets are distinguishable from legitimate endpoint RSTs by TTL: in the authors' 2006 experiments forged resets carried TTL=47 while genuine server packets carried TTL=39, consistent with the IDS sitting 8 hops closer to the client than the destination server. A 20-line FreeBSD kernel patch implementing TTL-divergence filtering was developed and demonstrated positive results in practice.

From 2006-clayton-ignoringIgnoring the Great Firewall of China · §7 · 2006 · Privacy Enhancing Technologies

Implications

Tags

censors
cn
techniques
rst-injection

Extracted by claude-sonnet-4-6 — review before relying.