FINDING · DETECTION

TapDance's non-blocking asymmetric design leaves the overt connection open but abandoned, enabling an active censor to inject a TCP ACK carrying a stale sequence number; the overt server responds with its true TCP state, exposing the discrepancy and confirming decoy routing. The attack requires no clean-path routing capability: the injected packet is forwarded through the tainted path by the non-blocking TapDance station itself.

From 2016-bocovich-slitheenSlitheen: Perfectly Imitated Decoy Routing through Traffic Replacement · §2.2, §4.3 · 2016 · Computer and Communications Security

Implications

Tags

censors
generic
techniques
active-probingrst-injection
defenses
tapdance

Extracted by claude-sonnet-4-6 — review before relying.