FINDING · DETECTION

The GFW blocks Tor primarily via stateless SYN/ACK dropping based on the server's source IP address and port (server-to-client direction, 73.04% of CN,Tor-dir cases). Two specific Tor directory authorities account for 98.8% of client-to-server (null-routed) blocks and 72.7% of error cases, indicating selective deeper blocking of specific IP addresses beyond the common return-path filter.

From 2014-ensafi-detectingDetecting Intentional Packet Drops on the Internet via TCP/IP Side Channels · §5 · 2014 · Passive and Active Measurement Conference

Implications

Tags

censors
cn
techniques
ip-blockingport-blocking
defenses
tor

Extracted by claude-sonnet-4-6 — review before relying.