FINDING · DEPLOYMENT
The MIT ANA Spoofer project shows that over 400 ASes (22%) and 88.7 million IP addresses (15.7%) permit outbound IP address spoofing, constraining where CensorSpoofer proxy nodes can be deployed. ASes applying ingress/egress filtering make IP-spoofing-based downstream channels infeasible from those locations.
From 2012-wang-censorspoofer — CensorSpoofer: Asymmetric Communication using IP Spoofing for Censorship-Resistant Web Browsing · §4.2 · 2012 · Computer and Communications Security
Implications
- Pre-screen candidate spoofer hosts using the MIT ANA Spoofer tool before deployment; only ~22% of ASes permit the outbound IP spoofing that this architecture requires.
- Plan for a small, curated pool of spoofer exit ASes rather than open volunteer deployment, as the majority of the address space cannot launch spoofed packets.
Tags
Extracted by claude-sonnet-4-6 — review before relying.