FINDING · DETECTION

Middlebox classification state is ephemeral: the testbed carrier-grade DPI device flushes results after 120 seconds (or 10 seconds after a TCP RST), and the GFC flushes state after 40–240 seconds depending on time of day. A strategically timed pause before the matching payload, or a TTL-limited RST packet, causes the classifier to re-evaluate the connection as unclassified traffic.

From 2017-li-lib-cdot-eratelib$\cdot$erate, (n): A library for exposing (traffic-classification) rules and avoiding them efficiently · §4.3, §5.3 · 2017 · Internet Measurement Conference

Implications

Tags

censors
cn
techniques
dpi

Extracted by claude-sonnet-4-6 — review before relying.