FINDING · EVALUATION
BGP simulation shows that a censor's source-block attack against 100 downstream-only decoy ASes disconnects 23% of Chinese Internet destinations, versus only 8% when applying the standard RAD attack against 100 upstream decoy ASes — imposing nearly 3× more unreachability collateral damage on the censor for the same decoy count.
From 2017-nasr-waterfall — The Waterfall of Liberty: Decoy Routing Circumvention that Resists Routing Attacks · §4.1.1, Figure 3 · 2017 · Computer and Communications Security
Implications
- Use downstream-only decoy routing to sharply raise the censor's self-harm cost: every attempt to evade decoy ASes disconnects disproportionately more of its own users from the open Internet.
- Select decoy ASes that appear on many downstream paths into the censored country to maximize the per-AS collateral damage the censor must absorb.
Tags
Extracted by claude-sonnet-4-6 — review before relying.