FINDING · DEFENSE

A circumvention strategy of holding DNS responses and filtering those matching the known forged-IP pool achieves 99.8% accuracy, correctly classifying 1,005,444,476 of 1,007,002,451 poisoned resolutions. From inside China, 99% of forged responses arrive within 364ms before the legitimate response, establishing 364ms as the recommended hold-on duration; from outside China, 11% of forged responses arrive after the legitimate one, making the IP-blocklist check necessary to avoid misclassifying genuine responses as poisoned.

From 2021-hoang-greatHow Great is the Great Firewall? Measuring China's DNS Censorship · §7.1, §7.2, Figure 11 · 2021 · USENIX Security Symposium

Implications

Tags

censors
cn
techniques
dns-poisoning

Extracted by claude-sonnet-4-6 — review before relying.