FINDING · EVALUATION

The GC acted probabilistically, responding to only approximately 1.75% of eligible requests (526 out of 30,000 from three measurement IP addresses) and completely ignoring one of four measurement source IPs. Flow-cache exhaustion tests confirmed the probabilistic decision is made per-flow at cache insertion time: once the ~16,000-entry cache was filled, injections resumed on previously-ignored source ports, ruling out connection-tuple hashing as the selection mechanism.

From 2015-marczak-analysisAn Analysis of China's ``Great Cannon'' · §3.1 · 2015 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
packet-injectionip-blocking

Extracted by claude-sonnet-4-6 — review before relying.