FINDING · DETECTION
A single GFW node employs approximately 360 distinct processes, load-balanced by source and destination IP address, which collectively inject censored DNS responses at an average rate of ~2,800 packets per second, ranging from 1,100 to 4,000 pps over a day.
From 2014-anonymous-towards — Towards a Comprehensive Picture of the Great Firewall's DNS Censorship · §7 · 2014 · Free and Open Communications on the Internet
Implications
- The GFW's injection rate (up to 4,000 pps per node) makes racing injected DNS responses infeasible — defense must prevent the query from reaching GFW-monitored links rather than outrunning forged replies.
- IP-based load balancing exposes a structural side-channel: circumvention researchers can fingerprint individual GFW processes via IP TTL and IP ID patterns to map node topology without triggering active countermeasures.
Tags
Extracted by claude-sonnet-4-6 — review before relying.