FINDING · DETECTION

Geneva experiments revealed that the GFW determines TCP three-way handshake completion using only the presence of the ACK flag — without validating sequence numbers. Upon receiving a RST or RST/ACK before the handshake completes, the GFW enters a resynchronization state approximately 50% of the time rather than tearing down its TCB; strategies that exploit this pre-handshake window achieve 92–95% success rates (Strategies 3 and 4).

From 2019-bock-genevaGeneva: Evolving Censorship Evasion Strategies · §5.2 Species 2: TCB Teardown · 2019 · Computer and Communications Security

Implications

Tags

censors
cn
techniques
dpirst-injection
defenses
geneva

Extracted by claude-sonnet-4-6 — review before relying.