FINDING · DETECTION

Iran's censor and AT&T's Stream Saver restrict DPI inspection strictly to port 80; traffic on any other TCP port escapes classification entirely. Iran additionally inspects the full flow (not just initial packets), unlike T-Mobile and the testbed device which only inspect the first few packets, making packet-count-based evasion insufficient against Iran on port 80.

From 2017-li-lib-cdot-eratelib$\cdot$erate, (n): A library for exposing (traffic-classification) rules and avoiding them efficiently · §1 (key findings), §6.3 · 2017 · Internet Measurement Conference

Implications

Tags

censors
ir
techniques
dpiport-blocking

Extracted by claude-sonnet-4-6 — review before relying.