FINDING · DETECTION
Geneva experiments revealed that the GFW determines TCP three-way handshake completion using only the presence of the ACK flag — without validating sequence numbers. Upon receiving a RST or RST/ACK before the handshake completes, the GFW enters a resynchronization state approximately 50% of the time rather than tearing down its TCB; strategies that exploit this pre-handshake window achieve 92–95% success rates (Strategies 3 and 4).
From 2019-bock-geneva — Geneva: Evolving Censorship Evasion Strategies · §5.2 Species 2: TCB Teardown · 2019 · Computer and Communications Security
Implications
- Target pre-handshake RST injection to exploit the GFW's handshake-state tracking gap — sending a corrupted RST before SYN-ACK with a paired ACK-corruption tree achieves 92% success.
- Model the GFW's ~50% resynchronization rate when assessing TCB Teardown reliability and pair teardown with complementary techniques to achieve consistent evasion.
Tags
Extracted by claude-sonnet-4-6 — review before relying.