The GFW is fully stateful as of 2010: probing all 11,824 Chinese IP prefixes with single TCP packets containing the keyword 'falun' produced no RST responses, confirming that a complete TCP handshake must precede any filtering trigger. Earlier measurements (2006, 2007) reported contradictory results; this study finds statefulness is now universal across all probed prefixes.
From 2011-xu-internet — Internet Censorship in China: Where Does the Filtering Occur?
· §4.1
· 2011
· Passive and Active Measurement Conference
Implications
Circumvention transports must complete a real TCP three-way handshake before sending any distinguishing payload; sending a bare probe packet or injecting keywords without a handshake will not reveal or trigger the censor.
Active-probing defenses can exploit statefulness: a server that silently drops or resets connections from unrecognized clients before completing a handshake avoids fingerprinting by stateful IDS probes.