FINDING · EVALUATION
China's AS-level topology is shallow and concentrated: CHINANET and CNCGROUP together account for 63.9% of 133 unique foreign peerings, 87% of internal ASes are within one hop of a border AS, and just 24 border/backbone ASes serve as effective choke points for all international traffic. The TTL of GFW RST packets is now crafted to prevent IDS localization by TTL inspection, requiring TTL-incrementing probe packets to identify filtering device positions.
From 2011-xu-internet — Internet Censorship in China: Where Does the Filtering Occur? · §3.2, §3.3, §2 · 2011 · Passive and Active Measurement Conference
Implications
- The extreme concentration of international peering in two ISPs means censors can achieve near-total international blocking with a small number of policy changes at CHINANET and CNCGROUP — circumvention infrastructure must treat AS-level diversity as a first-class design requirement, not just IP diversity.
- TTL-based IDS location fingerprinting is no longer viable against the GFW; circumvention measurement tooling must use TTL-incrementing ACK probes after triggering a reset, not passive TTL analysis of RST packets, to determine filtering device positions.
Tags
Extracted by claude-sonnet-4-6 — review before relying.