FINDING · DETECTION

GFW exhibits three confirmed HTTP analysis gaps: it inspects only the first Request-URI and Host header in HTTP-pipelined requests (HTTP3), will not scan beyond 2,048 bytes into a Request-URI (HTTP2), and recognizes only standard percent-encoding while ignoring alternative URI encodings such as overlong UTF-8 (HTTP4). The authors classify all three as low-difficulty fixes for the censor, meaning they may be patched quickly once disclosed.

From 2013-khattak-towardsTowards Illuminating a Censorship Monitor's Model to Facilitate Evasion · §5, Table 1 (HTTP2, HTTP3, HTTP4) · 2013 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
dpikeyword-filtering
defenses
mimicry

Extracted by claude-sonnet-4-6 — review before relying.