FINDING · DETECTION

Post-handshake tampering signatures (⟨SYN;ACK→RST⟩ and ⟨SYN;ACK→RST+ACK⟩) constitute 34.4% of tampered connections from Iranian networks, but over 70% from Sri Lanka networks and over 81% from Turkmenistan networks, suggesting that censors in the latter two countries disproportionately block at the IP/TCP-handshake level before any application-layer content is visible — consistent with IP-list-based blocking rather than SNI-based DPI.

From 2023-raman-globalGlobal, Passive Detection of Connection Tampering · §4.1 · 2023 · SIGCOMM

Implications

Tags

censors
irtm
techniques
rst-injectionip-blocking

Extracted by claude-sonnet-4-6 — review before relying.