FINDING · DETECTION

Chinese DNS censorship operates symmetrically — injecting forged responses for both inbound and outbound DNS packets regardless of whether any real service exists at the destination IP. This means any DNS response received for a probe sent to a closed-port IP inside China is unambiguously a censorship injection, not a legitimate resolver reply.

From 2022-bhaskar-manyMany Roads Lead To Rome: How Packet Headers Influence DNS Censorship Measurement · §3.1 · 2022 · USENIX Security Symposium

Implications

Tags

censors
cn
techniques
dns-poisoningpacket-injection

Extracted by claude-sonnet-4-6 — review before relying.