FINDING · DETECTION

China's censoring devices send four spoofed RST packets per filtered connection with varying sequence and ACK numbers and TTL values corresponding to roughly the hop count to the Chinese border; the IP ID field increments sequentially per TTL group, strongly implying a small cluster of out-of-band machines co-located at each border router. Because the device is out-of-band, the actual server response still arrives at the client but is preempted by the injected RSTs.

From 2012-verkamp-inferringInferring Mechanics of Web Censorship Around the World · §4.2 · 2012 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
rst-injectiondpi

Extracted by claude-sonnet-4-6 — review before relying.