FINDING · DEFENSE

SymTCP uses selective symbolic execution over Linux's TCP implementation (S2E + KLEE) to enumerate all packet sequences reaching 47 binary-level accept or drop points from LISTEN to ESTABLISHED, then conducts differential testing against a blackbox DPI to confirm discrepancies; the open-sourced system requires no DPI source access and covers 37 of 47 drop points within the operationally relevant handshake window.

From 2020-wang-symtcpSymTCP: Eluding Stateful Deep Packet Inspection with Automated Discrepancy Discovery · §IV, §VIII.A–B · 2020 · Network and Distributed System Security

Implications

Tags

censors
cngeneric
techniques
dpimiddlebox-interference
defenses
meta-resistancegeneva

Extracted by claude-sonnet-4-6 — review before relying.