The Great Firewall of China deploys at least four distinct, simultaneously-operating RST injectors with separate fingerprints (IPID 64, IPID -26, SEQ 1460, RAE). The RAE injector—which sets RST+ACK+ECN-nonce-sum flags—is the most common, with 4,162 distinct source IPs observed at UCB alone. Of 298 ICSI hosts disrupted by Chinese injectors, 102 showed fingerprints of two or more injectors acting independently on the same connection.
From 2009-weaver-detecting — Detecting Forged TCP Reset Packets
· §7.1.6
· 2009
· Network and Distributed System Security
Implications
Circumvention tools operating in China must handle multiple simultaneous RST injections per connection — ignoring one injector's RST is insufficient if a second injector fires independently on the same flow.
Device-level fingerprints (IPID constants, flag combinations, sequence increment patterns) can be used to build a blocklist for selectively dropping forged RSTs from known GFW injectors.