FINDING · DETECTION

The GFW evolved to create a TCB not only on SYN packets but also on SYN/ACK packets, and enters a 're-synchronization state' upon seeing multiple SYN packets, multiple SYN/ACK packets, or a SYN/ACK with an incorrect acknowledgment number. Once in this state, it re-synchronizes its TCB using the next client-to-server data packet or server SYN/ACK, invalidating prior TCB-creation evasion strategies that assumed the GFW used only the first SYN sequence number.

From 2017-wang-yourYour State is Not Mine: A Closer Look at Evading Stateful Internet Censorship · §4 · 2017 · Internet Measurement Conference

Implications

Tags

censors
cn
techniques
dpirst-injectionmiddlebox-interference

Extracted by claude-sonnet-4-6 — review before relying.