FINDING · DETECTION
An internet-wide scan of 500k IP addresses from an in-country VPS vantage point found TCP establishment-interception injections on 43,479 addresses (8.7% of scanned), with over 70% concentrated in two Akamai ASes (AS16625 and AS20940). The injection pattern — triggered by the first packet sent to these addresses — is consistent with targeted blocking of domain-fronting proxies hosted on Akamai CDN.
From 2025-alaraj-iran-refraction — Measuring Censorship in Iran Using Refraction-based Proxies · §4.1.2 · 2025 · ACM ASIA Conference on Computer and Communications Security
Implications
- Akamai CDN IPs used for domain fronting face pre-establishment TCP injection in Iran; operators should test CDN-specific blocking and consider rotating to CDN providers with smaller IP footprint (CloudFront, Fastly) that may not yet be targeted.
- Pre-establishment injection (before any application data) means SNI or content-based fingerprinting is not required; the censor is blocking the CDN IP range itself, not the TLS payload.
Tags
Extracted by claude-sonnet-4-6 — review before relying.