FINDING · DETECTION

TLS connections to blocked services (instagram.com, telegram.org) were terminated by TCP RST immediately after the client's ClientHello, before any certificate exchange, confirming SNI-based DPI that reads the plaintext SNI extension and aborts the handshake. HTTP filtering additionally matched Host headers and URL keywords case-sensitively, with injected HTTP 403 pages or TCP RST responses, and case-change evasions were sometimes effective.

From 2025-aryapour-stealth-blackoutIran's Stealth Internet Blackout: A New Model of Censorship · §4.2, §4.3 · 2025 · arXiv preprint (cs.NI)

Implications

Tags

censors
ir
techniques
sni-blockingdpirst-injectionkeyword-filtering

Extracted by claude-sonnet-4-6 — review before relying.