FINDING · DETECTION

GFW employs layered blocking for high-value targets: DNS poisoning for domains like google.com and wikipedia.org combined with null-routing of their hosting IPs, meaning packet-manipulation tools that operate at the TCP/HTTP layer (e.g., Geneva, DeResistor) cannot generate or test evasion strategies because no response is received to the initial SYN — the blocking occurs below the layer those tools target.

From 2023-amich-deresistorDeResistor: Toward Detection-Resistant Probing for Evasion of Internet Censorship · §6.1 · 2023 · USENIX Security Symposium

Implications

Tags

censors
cn
techniques
dns-poisoningip-blocking
defenses
geneva

Extracted by claude-sonnet-4-6 — review before relying.