FINDING · DETECTION

Iranian DNS censorship returns special-purpose/private IPv4 addresses in 99.99% of manipulated responses (only 0.01% public), whereas Chinese manipulation returns public IPs 99.46% of the time—often addresses that host no services at all. The 10 most frequent Chinese censor-injected IPs constituted approximately 75% of all Chinese manipulated DNS responses.

From 2017-pearce-globalGlobal Measurement of DNS Manipulation · §5.2, Table 8 · 2017 · USENIX Security Symposium

Implications

Tags

censors
cnir
techniques
dns-poisoning

Extracted by claude-sonnet-4-6 — review before relying.