FINDING · DETECTION

OONI's traffic manipulation test suite uses bidirectional traceroute comparison: asymmetry between inbound and outbound paths for specific source/destination port pairs is treated as an indicator that traffic is being diverted to an interception device. Additional per-flow indicators include timing differences in packets directed at specific ports and layer-7 header field manipulation detectable at the receiving endpoint.

From 2012-filast-ooniOONI: Open Observatory of Network Interference · §5.5 Traffic Manipulation · 2012 · Free and Open Communications on the Internet

Implications

Tags

techniques
dpimiddlebox-interferencepacket-injectiontraffic-shape

Extracted by claude-sonnet-4-6 — review before relying.