FINDING · EVALUATION
The SYN backlog side channel can detect censorship for any Internet host with an open port at approximately 5 packets per second without causing denial of service, provided only one measurement machine targets any given server at a time. Updated implementations require only that the backlog be half full rather than requiring full exhaustion, eliminating the earlier DoS requirement.
From 2015-crandall-forgive — Forgive Us our SYNs: Technical and Ethical Considerations for Measuring Internet Filtering · §3.3, Table 1 · 2015 · Ethics in Networked Systems Research
Implications
- Circumvention infrastructure operators can run low-rate SYN backlog scans from an external vantage point to detect on-path filtering of their proxy endpoints without deploying client software in the censored country.
- Restrict concurrent SYN backlog scans to one measurement machine per target server to stay below DoS thresholds on older Windows stacks.
Tags
Extracted by claude-sonnet-4-6 — review before relying.