FINDING · DEFENSE

The authors implement a system that identifies correct IP addresses of blocked domains inside a censored network by exploiting the predictable characteristics of forged IPs returned by GFW DNS filtering devices. The system achieves 100% accuracy in identifying valid IPs within a short time period, using 1.7 billion DNS records collected over 40 days across 86,876 resolvers.

From 2022-cheng-in-depthIn-Depth Evaluation of the Impact of National-Level DNS Filtering on DNS Resolvers over Space and Time · §6 (Abstract, §1 Introduction) · 2022 · Electronics

Implications

Tags

censors
cn
techniques
dns-poisoning
defenses
dns-tunneling

Extracted by claude-sonnet-4-6 — review before relying.