FINDING · DETECTION

GFW maintains TCP connection state for up to ≈10 hours and tolerates up to ≈1 GB of client-to-server data, but drastically reduces these limits when a sequence hole exists: it abandons state after buffering only 1 KB above the hole (TCP9) and times out holed connections in 60–90 minutes rather than ≈10 hours (TCP10). These thresholds were confirmed over repeated measurements and represent the maxima tested, not precise censor-configured limits.

From 2013-khattak-towardsTowards Illuminating a Censorship Monitor's Model to Facilitate Evasion · §5, Table 1 (TCP9, TCP10) · 2013 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
dpikeyword-filteringrst-injection
defenses
geneva

Extracted by claude-sonnet-4-6 — review before relying.