FINDING · DETECTION
The GFW's active probers originate from thousands of distinct IP addresses, but a network-level side-channel (shared IP ID counter sequences) reveals they are controlled by a small number of centralized structures. Probe delay from legitimate connection to first active probe can be as short as 0.28 seconds, ruling out any reactive defense that relies on out-of-band blocking before probes arrive.
From 2020-alice-shadowsocks-detection — How China Detects and Blocks Shadowsocks · §3.3, §3.5 · 2020 · IMC
Implications
- Do not rely on IP allowlisting or rate-limiting to deflect probes; the prober pool is large (thousands of IPs) and probes arrive within sub-second latency.
- Server-side probe handling must be synchronous with connection acceptance, not an asynchronous background process.
Tags
Extracted by claude-sonnet-4-6 — review before relying.