A Wall Behind A Wall:
Emerging Regional Censorship in China
Mingshi Wu* (GFW Report), Ali Zohaib* (UMass Amherst),
Project Homepage
Zakir Durumeric (Stanford University), Amir Houmansadr (UMass Amherst), Eric Wustrow (CU Boulder)
Discovering Regional Censorship Henan Firewall v.s. The Great Firewall (GFW) Comparing the Blocklists
China has long employed centralized blocking policies We measure the Henan Firewall and compare it with the GFW: the
and implementations, namely the Great Firewall of China. Henan Firewall is less sophisticated and exhibits more parsing aws.
Henan
In August 2023, users in Henan province reported losing Firewall GFW
access to some websites that were still reachable
elsewhere in China. China US
SYN
SYN+ACK
ACK
PSH+ACK
SNI: youtube.com
Provincial Firewall GFW
Type I RST x1 RST x1
Type II RST+ACK x3 RST+ACK x3
Type III RST+ACK x1 RST+ACK x1
Henan has deployed its own HTTP Host-based & TLS
SNI-based rewall to censor traf c leaving the province.
New r!
Injecto
Guangdong
Chongqing
S E R V E R S
No TCP Connection Established
Shanghai
Sichuan
Jiangsu
PSH+ACK
Beijing
Henan
Henan SNI: 011.com
Henan Firewall’s blocking is more
C L I E N T S
RST+ACK x1
Beijing 0 0 0 0 0 0 0
aggressive and volatile than the GFW
due to its frequent blocking and
Sichuan 0 0 0 0 0 0 0
10 bytes payload: 0x 01 02 03 04 05 06 07 08 09 00 unblocking of generic second-level
7 hops away: Backbone China Unicom
Chongqing 0 0 0 0 0 0 0
5 hops away: China Unicom Province Network domains (e.g., *.org.uk, *.com.au). It once
Guangdong 0 0 0 0 0 0 0 blocked 10× more domains than the GFW.
Circumvention Strategies
Jiangsu 0 0 0 0 0 0 0
Shanghai 0 0 0 0 0 0 0
Client-Side Circumvention Strategies GFW
Henan
Firewall Takeaways
Henan 123 122 122 122 124 122 0 TCP Segmentation ✘ ✔ • China’s Internet censorship is no longer
TLS Fragmentation ✔ ✔ strictly centralized.
Blocked‑domain counts per client→server pair, based on
TLS probes using SNIs from the top 10K Tranco domains. Enable any TCP options (e.g. Timestamps), • Fragmented regional censorship
✘ ✔
making TCP Header Length > 20 bytes complicates both measurement &
No evidence of inter-provincial blocking in any other
Ignore TCP RSTs with payload ✘ ✔ circumvention e orts.
tested regions; Henan is the rst con rmed case.
fi
ff
fi
fi
fi
fl