FINDING · EVALUATION

TCP segment splitting and out-of-order delivery evades DPI classification in the testbed, T-Mobile, and Iran, but fails against the GFC—which performs extensive packet validation and correctly reassembles reordered streams—and AT&T, which uses a transparent HTTP proxy that normalizes all traffic before inspection. Payload splitting to one byte in the first packet is sufficient to defeat packet-count-limited classifiers.

From 2017-li-lib-cdot-eratelib$\cdot$erate, (n): A library for exposing (traffic-classification) rules and avoiding them efficiently · §4.3, Table 3 · 2017 · Internet Measurement Conference

Implications

Tags

censors
cnir
techniques
dpimiddlebox-interference
defenses
meta-resistance

Extracted by claude-sonnet-4-6 — review before relying.