FINDING · DETECTION

The GFW's active probers originate from thousands of distinct IP addresses, but a network-level side-channel (shared IP ID counter sequences) reveals they are controlled by a small number of centralized structures. Probe delay from legitimate connection to first active probe can be as short as 0.28 seconds, ruling out any reactive defense that relies on out-of-band blocking before probes arrive.

From 2020-alice-shadowsocks-detectionHow China Detects and Blocks Shadowsocks · §3.3, §3.5 · 2020 · IMC

Implications

Tags

censors
cn
techniques
active-probing

Extracted by claude-sonnet-4-6 — review before relying.