FINDING · DETECTION
The GFW is fully stateful as of 2010: probing all 11,824 Chinese IP prefixes with single TCP packets containing the keyword 'falun' produced no RST responses, confirming that a complete TCP handshake must precede any filtering trigger. Earlier measurements (2006, 2007) reported contradictory results; this study finds statefulness is now universal across all probed prefixes.
From 2011-xu-internet — Internet Censorship in China: Where Does the Filtering Occur? · §4.1 · 2011 · Passive and Active Measurement Conference
Implications
- Circumvention transports must complete a real TCP three-way handshake before sending any distinguishing payload; sending a bare probe packet or injecting keywords without a handshake will not reveal or trigger the censor.
- Active-probing defenses can exploit statefulness: a server that silently drops or resets connections from unrecognized clients before completing a handshake avoids fingerprinting by stateful IDS probes.
Tags
Extracted by claude-sonnet-4-6 — review before relying.