FINDING · DEFENSE

Endpoints that never close a connection and never respond to any probe ('infinite timeout') represent 0.7% of the ISP Tap dataset and 42% of the ZMap active-scan dataset; this is the single most common probe-indifferent behavior in both datasets. MTProto already exploits this: its strategy of keeping failed connections open indefinitely produces the highest false-positive rate (0.56% of Tap) among all tested protocols, making it effectively uncountable at acceptable collateral-damage thresholds.

From 2020-frolov-detectingDetecting Probe-resistant Proxies · §VI, Fig. 13 · 2020 · Network and Distributed System Security

Implications

Tags

censors
generic
techniques
active-probing
defenses
pluggable-transportobfs4shadowsocks

Extracted by claude-sonnet-4-6 — review before relying.