FINDING · DETECTION

DNS censorship complexity varies sharply by country: Iran injects static forged IPs exclusively from 10.0.0.0/8 and Turkmenistan uses only 127.0.0.1, making detection trivial, while China's constant fake-IP churn across ASes demands dynamic ML approaches; models trained without country-specific ASN features still perform well, enabling transfer to countries where GFWatch-equivalent infrastructure does not exist.

From 2023-brown-augmentingAugmenting Rule-based DNS Censorship Detection at Scale with Machine Learning · §5 · 2023 · Knowledge Discovery And Data Mining

Implications

Tags

censors
cnirtm
techniques
dns-poisoningml-classifier

Extracted by claude-sonnet-4-6 — review before relying.