FINDING · DETECTION

An internet-wide scan of 500k IP addresses from an in-country VPS vantage point found TCP establishment-interception injections on 43,479 addresses (8.7% of scanned), with over 70% concentrated in two Akamai ASes (AS16625 and AS20940). The injection pattern — triggered by the first packet sent to these addresses — is consistent with targeted blocking of domain-fronting proxies hosted on Akamai CDN.

From 2025-alaraj-iran-refractionMeasuring Censorship in Iran Using Refraction-based Proxies · §4.1.2 · 2025 · ACM ASIA Conference on Computer and Communications Security

Implications

Tags

censors
ir
techniques
packet-injectionrst-injectionip-blocking
defenses
domain-fronting

Extracted by claude-sonnet-4-6 — review before relying.