FINDING · EVALUATION

Internet-wide IPv4 scanning found 386,187 IP addresses yielding amplification factors ≥ 100× via TCP middlebox reflection, with 82.9% of responses from the top 1 million IPs confirmed as originating from on-path middleboxes rather than endpoints. Nation-state censorship infrastructure dominates: China's GFW alone accounts for approximately 154 million responding IP addresses sharing a 3× RST+ACK (54 bytes each) fingerprint.

From 2021-bock-weaponizingWeaponizing Middleboxes for TCP Reflected Amplification · §5.3, §5.5, Table 4 · 2021 · USENIX Security Symposium

Implications

Tags

censors
cnirsaru
techniques
middlebox-interferencerst-injectionpacket-injectionmeasurement-platform

Extracted by claude-sonnet-4-6 — review before relying.