FINDING · DETECTION

TCP fragmentation before the SNI extension circumvents the GFW, but TCP fragmentation placing the SNI in the first TCP segment does not. The paper notes the GFW is showing 'the first signs of successfully handling TCP fragmentation,' indicating active hardening of TCP-layer circumvention that makes TLS-layer techniques increasingly necessary.

From 2023-niere-posterPoster: Circumventing the GFW with TLS Record Fragmentation · §3, Table 1 · 2023 · ACM CCS 2023 (poster)

Implications

Tags

censors
cn
techniques
sni-blockingdpi

Extracted by claude-sonnet-4-6 — review before relying.