FINDING · EVALUATION

In approximately 100,000 DNS queries over 9 days from within a censored network, injected packets were reliably distinguishable: legitimate IP TTLs were stable at either 44 or 42, while injected TTL values ranged across [0–255], and injected packets arrived well before legitimate replies because the injector co-resided within the same ISP while the recursive resolver was in another country. With a TTL threshold of ±1 and an RTT threshold of 0.5× expected RTT, the Hold-On prototype achieved 0% false positive rate and 0% false negative rate.

From 2012-duan-hold-onHold-On: Protecting Against On-Path DNS Poisoning · §IV.B, Table I · 2012 · Securing and Trusting Internet Names

Implications

Tags

censors
cn
techniques
dns-poisoningpacket-injection

Extracted by claude-sonnet-4-6 — review before relying.