FINDING · EVALUATION

SymTCP generated 56,787 candidate insertion/evasion packets in approximately one hour using concolic execution over Linux's TCP stack. Evaluating a sampled set of 10,000 test cases against real DPI systems yielded 6,082 evasions against Zeek, 652 against Snort, and 4,587 against the Great Firewall of China — discovering 14 novel evasion strategies beyond those found by prior manual approaches.

From 2020-wang-symtcpSymTCP: Eluding Stateful Deep Packet Inspection with Automated Discrepancy Discovery · §VIII.C · 2020 · Network and Distributed System Security

Implications

Tags

censors
cngeneric
techniques
dpimiddlebox-interference
defenses
genevameta-resistance

Extracted by claude-sonnet-4-6 — review before relying.