FINDING · DETECTION

The Great Cannon (GC) operates as a distinct in-path system — not an extension of the GFW — capable of both injecting and suppressing traffic, enabling full man-in-the-middle capability against targeted IP addresses. Unlike the on-path GFW, the GC only examines the first data packet of each connection (avoiding TCP bytestream reassembly), targets specific destination IP addresses rather than all border traffic, and maintains a per-source-IP flow cache of approximately 16,000 entries to ignore already-processed connections.

From 2015-marczak-analysisAn Analysis of China's ``Great Cannon'' · §3, §3.1 · 2015 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
packet-injectiondpiip-blocking

Extracted by claude-sonnet-4-6 — review before relying.