FINDING · DETECTION

Iran's censorship of refraction-networking proxies (Conjure via Psiphon) is not monolithic: different ISPs independently deploy different techniques and timelines. Over 800 million logged Conjure connections from July 2023–February 2025 across 10+ Iranian ASes show TCI (AS58224, ~33% of traffic) uses packet injection, while MCCI/Hamrah-e Avval (AS197207, ~22%) applies IP-based blocking, and some ASes (Parsonline AS16322, Shatel AS31549) show no proxy blocking at all.

From 2025-alaraj-iran-refractionMeasuring Censorship in Iran Using Refraction-based Proxies · §4 · 2025 · ACM ASIA Conference on Computer and Communications Security

Implications

Tags

censors
ir
techniques
rst-injectionip-blockingpacket-injectiondpi
defenses
decoy-routingconjure

Extracted by claude-sonnet-4-6 — review before relying.