FINDING · DETECTION

Censoring middleboxes predominantly use RST injection rather than in-path packet dropping because injecting forged RST/RST+ACK packets does not require the middlebox to sit in the data path — off-path copies of packets suffice. The GFW specifically injects both RST and RST+ACK packets simultaneously after an offending PSH, a known idiosyncratic signature, while Iran's censor uses post-handshake RST injection (⟨SYN;ACK→RST⟩) and packet drops at the same stage.

From 2023-raman-globalGlobal, Passive Detection of Connection Tampering · §2.1, §4.1 · 2023 · SIGCOMM

Implications

Tags

censors
cnir
techniques
rst-injectiondpisni-blocking

Extracted by claude-sonnet-4-6 — review before relying.