FINDING · DETECTION

The GFW's dominant exploitable discrepancy is accepting data packets whose TCP sequence number is ≤ the initial sequence number (ISN), while Linux rejects such packets as out-of-window. This single 'SEQ ≤ ISN' strategy accounts for the majority of the 3,152 successful evasion-packet cases against the GFW out of 4,587 total successful evasions.

From 2020-wang-symtcpSymTCP: Eluding Stateful Deep Packet Inspection with Automated Discrepancy Discovery · §VIII.C · 2020 · Network and Distributed System Security

Implications

Tags

censors
cn
techniques
dpimiddlebox-interference
defenses
geneva

Extracted by claude-sonnet-4-6 — review before relying.