FINDING · DETECTION

Nation-state censors produce characteristic TCP response fingerprints: China's GFW sends 3× RST+ACK (54 bytes each) from ~170 million IPs; Iran's infrastructure sends 402–405-byte FIN+PSH+ACK plus 54-byte RST+PSH+ACK from 8.6 million IPs (75.7% of responsive Iranian addresses); Saudi Arabia sends a 97-byte PSH+ACK plus 2× 1,354-byte PSH+ACKs at 18.9× amplification from 400,000+ IPs. Most nation-state censors produce less than 4× amplification due to compact block pages.

From 2021-bock-weaponizingWeaponizing Middleboxes for TCP Reflected Amplification · §5.5, Table 4 · 2021 · USENIX Security Symposium

Implications

Tags

censors
cnirsaru
techniques
rst-injectionpacket-injectionmiddlebox-interference

Extracted by claude-sonnet-4-6 — review before relying.