FINDING · DETECTION

Stateful firewalls used as censorship middleboxes exhibit counter-intuitive implementation behaviors: FW-3 forwards ACK packets before a TCP handshake is initiated, and FW-1 actively spoofs RST packets in response to unsolicited traffic to thwart evasion attempts. These vendor-specific quirks create or close evasion opportunities that are invisible to rule-verification tools and not predictable from policy documentation alone.

From 2024-moon-prydePryde: A Modular Generalizable Workflow for Uncovering Evasion Attacks Against Stateful Firewall Deployments · §1 Introduction, Findings 3–4 · 2024 · Symposium on Security \& Privacy

Implications

Tags

censors
generic
techniques
middlebox-interferencerst-injection

Extracted by claude-sonnet-4-6 — review before relying.