FINDING · DETECTION

After a censored connection, 50–75% of subsequent connections from the same client IP to the same server IP and port are blocked for 90 seconds even without censored keywords ("penalty box"). The penalty box is strictly scoped to the (client IP, server IP, server port) triple — other ports at the same server IP or other server IPs are unaffected. The GFW monitors HTTP keyword traffic on every TCP port, not just port 80.

From 2021-rambert-chineseChinese Wall or Swiss Cheese? Keyword filtering in the Great Firewall of China · §4.4, §4.5 · 2021 · WWW

Implications

Tags

censors
cn
techniques
keyword-filteringrst-injectionport-blocking

Extracted by claude-sonnet-4-6 — review before relying.