Is Nobody There? Good! Globally Measuring Connection Tampering without Responsive Endhosts
Sadia Nourin, Erik Rye, Kevin Bock, Nguyen Phong Hoang, Dave Levin
IEEE Symposium on Security and Privacy 2025 · Day 2 · Censorship and Traffic Analysis
Overview
This talk introduces Mint (Measuring Interference with Non-responsive Targets), a groundbreaking tool designed to conduct global network interference measurements without the need for responsive end hosts within the target networks. Presented by Sadia Nourin and her co-authors, Mint addresses a critical limitation in existing censorship and network interference detection methodologies. Traditional tools, such as Ooni, Sensor Planet, and IC lab, rely on in-country participants, servers, or VPNs, which severely restricts their ability to measure interference in regions with low internet penetration, oppressive regimes, or poor infrastructure, and makes large-scale IPv6 measurements nearly impossible.

Key moments
- 0:00 Introduction to network interference measurement challenges
- 1:47 Introducing Mint: Measuring interference with non-responsive targets
- 3:04 Key network features enabling Mint's measurement approach
- 4:00 Exploiting TCP non-compliance with custom packet sequences
- 5:11 Mint's two-step scanning methodology explained
- 6:05 Global interference measurement results (IPv4 and IPv6 maps)
- 7:00 Mint's broader reach compared to OONI and Sensor Planet
Is Nobody There? Good! Globally Measuring Connection Tampering without Responsive Endhosts
Speakers: Sadia Nourin, Erik Rye, Kevin Bock, Nguyen Phong Hoang, Dave Levin
Conference: IEEE S&P
YouTube: https://www.youtube.com/watch?v=6BScomrd29k
Overview
This talk introduces Mint (Measuring Interference with Non-responsive Targets), a groundbreaking tool designed to conduct global network interference measurements without the need for responsive end hosts within the target networks. Presented by Sadia Nourin and her co-authors, Mint addresses a critical limitation in existing censorship and network interference detection methodologies. Traditional tools, such as Ooni, Sensor Planet, and IC lab, rely on in-country participants, servers, or VPNs, which severely restricts their ability to measure interference in regions with low internet penetration, oppressive regimes, or poor infrastructure, and makes large-scale IPv6 measurements nearly impossible.
Mint revolutionizes this landscape by probing non-responsive IP addresses, exploiting specific behaviors of middleboxes and the inherent vastness of unused IP space, particularly in IPv6. By circumventing the need for cooperative end hosts, Mint enables researchers to conduct both broad measurements across numerous networks and deep measurements testing a multitude of domains at high rates without ethical concerns related to affecting live systems. The tool represents a significant leap forward, offering the first global active network interference measurement of HTTP and HTTPS without responsive end hosts, and uniquely, the first scalable measurement of IPv6 interference.
The significance of Mint extends beyond merely detecting interference; it provides unprecedented capabilities for analyzing the underlying mechanisms and policies. For instance, Mint allows researchers to quantify the centralization of interference infrastructure and policy within different countries, revealing insights into how nation-states and organizations implement censorship. This capability opens new avenues for understanding the global landscape of network control and its evolution.
Background
▶ Watch: Introduction to network interference measurement challenges (0:00)
The pervasive nature of network interference, ranging from nation-state censorship to corporate intrusion detection systems, presents a significant challenge to internet freedom and open access to information. Understanding the scope and mechanisms of this interference is crucial for both defenders and those seeking to circumvent restrictions. However, current global measurement tools face substantial hurdles.
Existing platforms like Ooni (Open Observatory of Network Interference), Sensor Planet, and IC lab are fundamentally limited by their reliance on in-country infrastructure or participants. Ooni depends on local volunteers running measurement probes; Sensor Planet deploys servers within target countries; and IC lab utilizes VPNs to route traffic. These dependencies create several problems:
- Geographic Limitation: Measurements are confined to regions where it's safe and feasible to deploy servers or recruit participants. This leaves many networks, especially in countries with small populations, low internet penetration, highly oppressive regimes, or poor internet infrastructure, largely unmeasurable.
- Ethical and Practical Concerns: Engaging in-country participants or deploying servers carries inherent risks, both for the individuals involved and for the operational security of the measurement platform itself. High probing rates could also inadvertently affect live end hosts, leading to ethical dilemmas.
- IPv6 Blind Spot: The vast majority of IPv6 addresses remain unused, making it exceedingly difficult to find responsive end hosts for measurement purposes. Consequently, global IPv6 interference measurements have been virtually non-existent. Ooni offers some IPv6 measurement, but only if an Ooni participant's network supports V6 connectivity, which is a significant constraint.
Mint builds upon the foundational concepts explored in earlier studies like TMC (Turkmenistan Measurement Campaign) and GF Web (Great Firewall Web). These predecessors demonstrated the viability of detecting interference by probing non-responsive targets but were restricted to specific countries (Turkmenistan and China, respectively) and exclusively focused on IPv4. Mint generalizes this technique, extending its reach to virtually every country and network with non-responsive IP addresses, and crucially, incorporating comprehensive IPv6 measurement capabilities. This evolution from country-specific, IPv4-only studies to a global, dual-stack measurement tool represents a pivotal advancement in the field of internet censorship research.
Key Findings
▶ Watch: Key network features enabling Mint's measurement approach (3:04)
Mint's novel approach yielded several significant findings, demonstrating its efficacy and superior reach compared to existing tools:
- Broad and Deep Measurement Capabilities:
- HTTP IPv4 Interference: Mint successfully triggered interference in over 75% of the
/24prefixes probed in numerous countries, including Yemen, China, and Uzbekistan. This highlights its ability to measure interference broadly across diverse geopolitical landscapes. - HTTP IPv6 Interference: For IPv6, Mint triggered interference in greater than 90% of the
/48prefixes probed in countries like China, Uzbekistan, and Jordan. This is a monumental achievement, marking the first time IPv6 interference has been measured at scale.
- Comparative Advantage over Existing Tools:
- Mint vs. Sensor Planet (HTTP IPv4): Mint demonstrated a significantly broader reach, measuring interference in 6,348 more Autonomous Systems (ASs) over HTTP IPv4 than Sensor Planet. While Sensor Planet still reached some ASs Mint could not, Mint's overall expansion of measurable networks is substantial.
- Mint vs. Ooni (HTTP IPv6): Ooni was able to measure 931 more ASs than Mint over HTTP IPv6. This discrepancy might be attributed to Ooni's in-country participants potentially covering a wider range of IPv6 prefixes than the active
/48prefixes collected by Mint from NTP servers. However, Mint offers a critical advantage: within the ASs it can reach, it can scan far more broadly (millions of domains) compared to Ooni's participants, who are typically limited to testing a few domains per AS due to resource and ethical constraints.
- Prevalence of Enabling Network Features:
- Bidirectional Interference: The study confirmed that almost every country exhibits some level of bidirectional interference. This phenomenon, where middleboxes are agnostic to whether the client or server is inside the network deploying interference, is crucial for Mint's external measurement capabilities.
- TCP Non-Compliance: A significant percentage of networks were found to be non-compliant with the TCP protocol in ways that Mint could exploit. Approximately 8.5% of
/24IPv4 prefixes (representing around 15 million prefixes) and a higher 33% of/48IPv6 prefixes exhibited this non-compliance, meaning their middleboxes would tamper with connections even without a proper TCP 3-way handshake. - Abundance of Non-Responsive IPs: Critically, Mint's technique relies on sending probes to unused IP addresses. The research confirmed that over 90% of all
/24IPv4 prefixes and 100% of all/48IPv6 prefixes probed contained at least one non-responsive IP address, ensuring a vast target space for Mint.
- Novel Insights into Interference Centralization: Mint enabled entirely new types of studies, such as quantifying the centralization of interference mechanisms and policies:
- Infrastructure Centralization: By calculating the coefficient of variance (COV) of the packet sequences that triggered interference, Mint could infer the centralization of underlying infrastructure. A lower COV indicates that interference is triggered by similar packet sequences, suggesting a centralized system (e.g., Turkmenistan). A higher COV points to more variation and decentralization (e.g., the United States).
- Policy Centralization: Similarly, by analyzing the COV of domains that triggered interference, Mint could assess the centralization of interference policies. A lower COV implies networks block the same set of domains (centralized policy), while a higher COV suggests a wider variety of blocked domains (decentralized policy). These results mirrored the infrastructure findings, with countries like Turkmenistan showing highly centralized blocking policies and the US exhibiting decentralized ones.
These findings collectively underscore Mint's transformative potential, not just for detecting censorship, but for deeply analyzing its technical and political dimensions.
Technical Deep Dive
▶ Watch: Exploiting TCP non-compliance with custom packet sequences (4:00)
Mint's core innovation lies in its ability to measure network interference by sending probes to non-responsive IP addresses—IP addresses that do not have a live machine behind them. This strategy fundamentally bypasses the need for in-country participation, addressing the severe limitations of previous measurement platforms. To achieve this, Mint leverages three critical features of how networks and their middleboxes operate:
- Bidirectional Interference:
- This phenomenon refers to middleboxes that are agnostic to the direction of traffic flow relative to the interfering network. In simpler terms, a middlebox will apply its tampering rules whether the client or the server is located within the network deploying the interference.
- Mint relies on this characteristic because it allows measurements to be initiated from outside the country or network of study. The research found that bidirectional interference is prevalent in essentially every country, making external probing a widely applicable strategy. This means an external client can send a request that appears to originate from within the target network (even if it's spoofed or directed at a non-responsive IP), and if a middlebox intercepts it, it will respond (or tamper) as if it were an internal communication.
- TCP Non-Compliance of Middleboxes:
- Many network middleboxes (such as firewalls, IDPS, or censorship devices) do not strictly adhere to the TCP protocol specification. Specifically, Mint exploits cases where a middlebox will still act to tamper a connection even if it doesn't observe a proper TCP 3-way handshake (SYN, SYN-ACK, ACK) that typically precedes a sensitive HTTP/HTTPS request.
- The researchers designed six different custom packet sequences that can "trick" these non-compliant middleboxes into tampering with the connection. These sequences are crafted to bypass the handshake requirement, prompting the middlebox to intervene without any packets being returned from the (non-responsive) target IP address within the country of study.
- Mint's scans revealed that approximately 8.5% of the
/24IPv4 prefixes (amounting to roughly 15 million prefixes globally) exhibited this TCP non-compliance. For IPv6, the prevalence was even higher, at 33% of the/48prefixes. This widespread non-compliance is a cornerstone of Mint's ability to operate without live end hosts.
- Prevalence of Non-Responsive IP Addresses:
- For Mint to function, there must be a sufficient number of non-responsive IP addresses available to probe. The study confirmed that this is indeed the case: more than 90% of all
/24IPv4 prefixes and 100% of all/48IPv6 prefixes that were probed contained at least one non-responsive IP. - This abundance is particularly critical for IPv6, where the vast address space means a significant proportion of addresses are unused. This makes IPv6 an ideal environment for Mint's technique, enabling the first large-scale measurements of V6 interference.
Mint's Scanning Methodology
Mint employs a two-step scanning methodology:
- Finding Non-Responsive Hosts:
- The first step involves identifying suitable non-responsive IP addresses. Mint uses Zmap, a fast network scanner, to conduct a TCP SYN scan over all
/24IPv4 prefixes and active/48IPv6 prefixes. The active IPv6 prefixes were collected from known NTP servers, providing a practical starting point for the vast IPv6 space. - Any IP addresses that respond to these SYN probes are then omitted from the target list, leaving only the truly non-responsive ones. This ensures that no live end hosts are inadvertently affected by subsequent, more aggressive probing.
- Sending Custom Packet Sequence Probes:
- Once a list of non-responsive IP addresses is compiled, Mint sends its custom probes to these targets. These probes utilize the six different packet sequences developed to trick non-compliant middleboxes.
- The probes incorporate 460 different domains to test a wide range of potential censorship targets.
- This entire process is repeated twice: once for HTTP and once for HTTPS, to cover both common web protocols.
By leveraging these technical foundations and a robust scanning methodology, Mint significantly reduces ethical concerns associated with network interference measurement, as it avoids any interaction with live machines or in-country participants. This allows for higher scan rates and deeper measurements, testing millions of domains without fear of affecting operational networks.
Demo / Proof of Concept
▶ Watch: Global interference measurement results (IPv4 and IPv6 maps) (6:05)
While the talk does not describe a live, interactive demonstration of the Mint tool, the entire presentation serves as a comprehensive proof of concept for its methodology. The researchers thoroughly explain how Mint works, detailing the underlying network characteristics it exploits and the specific two-step scanning process.
The "Demo / Proof of Concept" is substantiated by the extensive measurement results presented, which directly validate Mint's ability to trigger and detect interference across a global scale. The maps illustrating the prevalence of interference in /24 IPv4 and /48 IPv6 prefixes (e.g., >75% in Yemen, China, Uzbekistan for IPv4; >90% in China, Uzbekistan, Jordan for IPv6) demonstrate that the technique is effective in practice. Furthermore, the quantitative comparisons with existing tools like Sensor Planet and Ooni, showing Mint's expanded reach and unique IPv6 capabilities, serve as strong empirical evidence of its operational success. The ability to derive complex insights, such as the centralization of interference policies based on the coefficient of variance of packet sequences and domains, further confirms the robustness and analytical power of the Mint methodology. Therefore, the talk provides a detailed exposition and empirical validation of Mint as a functional and impactful system.
Defensive Implications
▶ Watch: Mint's broader reach compared to OONI and Sensor Planet (7:00)
Mint's findings and methodology have profound implications for various stakeholders involved in network security, censorship, and internet freedom.
For Network Operators and Governments deploying middleboxes for security or censorship:
- Visibility of External Measurement: Mint demonstrates that network interference, even that intended to be covert or localized, can be measured and analyzed externally without the need for in-country cooperation. This means that operators can no longer assume their interference mechanisms are opaque to external observers.
- Middlebox TCP Non-Compliance: The revelation that a significant percentage of middleboxes (8.5% of IPv4 /24s, 33% of IPv6 /48s) are TCP non-compliant and can be "tricked" into tampering without a full 3-way handshake is a critical finding. Operators need to be aware that their devices might be behaving in ways that expose their presence or policies, potentially leading to unintended interference or circumvention opportunities. Strict adherence to TCP standards, or at least an understanding of non-compliant behaviors, is crucial for predictable network operations.
- Policy Centralization Analysis: The ability to quantify the centralization of interference infrastructure and policy provides a new metric for evaluating the effectiveness and characteristics of censorship regimes. Governments seeking to maintain tight control might view decentralized interference as less effective or harder to manage, while those seeking plausible deniability might find it useful. This information can influence future policy decisions and implementation strategies.
For Internet Users and Advocates for Internet Freedom:
- Empowerment through Data: Mint provides a powerful, ethical, and scalable tool for monitoring and documenting network interference globally. This data is invaluable for human rights organizations, journalists, and researchers working to expose censorship and advocate for internet freedom.
- Informed Circumvention Strategies: Understanding the technical nuances of interference (e.g., specific packet sequences that trigger tampering) and the level of centralization can inform the development of more effective circumvention tools and strategies. For instance, if censorship is highly centralized, a single circumvention technique might be broadly effective. If it's decentralized, more adaptive or diverse approaches might be needed.
- IPv6 Censorship Awareness: The ability to measure IPv6 interference at scale is particularly significant. As IPv6 adoption grows, understanding how censorship extends to this new protocol space becomes critical for ensuring future internet openness. Mint provides the first comprehensive look into this previously dark area.
For Security Researchers and Network Measurement Communities:
- New Measurement Paradigm: Mint introduces a novel and ethically sound methodology for global internet measurement, particularly for sensitive topics like censorship. This opens up new research avenues that were previously constrained by practical and ethical limitations.
- Tool for Network Diagnostics: Beyond censorship, the techniques employed by Mint could be adapted to diagnose other forms of network anomalies or middlebox behaviors, even in non-censorship contexts.
- Ethical Research: By eliminating the need for in-country participants or live end hosts, Mint significantly reduces the ethical complexities and risks associated with interference measurement, setting a precedent for responsible research in this domain.
- Understanding Middlebox Behavior: The detailed analysis of TCP non-compliance contributes to a broader understanding of how middleboxes deviate from protocol specifications and how these deviations can be leveraged for measurement or exploited for other purposes.
In essence, Mint shifts the balance of power, providing external observers with unprecedented visibility into the inner workings of network interference, pushing network operators towards greater transparency and potentially more protocol-compliant behavior, and empowering internet users with better tools and data to navigate a restricted internet.
Key Takeaways
- Global Measurement without End Hosts: Mint is the first tool to actively measure HTTP and HTTPS network interference globally without requiring responsive end hosts inside target countries, overcoming significant limitations of prior methods.
- Exploiting Network Behaviors: The methodology relies on three key network characteristics: widespread bidirectional interference, common TCP non-compliance in middleboxes (8.5% of IPv4 /24s, 33% of IPv6 /48s), and the abundance of non-responsive IP addresses.
- First Scalable IPv6 Interference Measurement: Mint is the first tool capable of measuring IPv6 network interference at scale, revealing significant tampering in IPv6 prefixes in countries like China, Uzbekistan, and Jordan.
- Expanded Reach: Mint significantly expands the scope of measurable networks, detecting interference in 6,348 more ASs over HTTP IPv4 than Sensor Planet, and providing broader domain testing within ASs compared to Ooni for IPv6.
- Quantifying Centralization: The tool enables novel studies to quantify the centralization of interference infrastructure and policies within countries, providing insights into the technical and political architectures of censorship.
- Reduced Ethical Concerns: By exclusively probing non-responsive IP addresses, Mint eliminates the ethical and practical risks associated with involving in-country participants or affecting live end hosts, allowing for higher scan rates and deeper analysis.
About the Speaker(s)
The primary presenter of the talk was Sadia Nourin. She, along with her co-authors Erik Rye, Kevin Bock, Nguyen Phong Hoang, and Dave Levin, conducted the research on Mint. The transcript does not provide specific titles or affiliations for the speakers, focusing instead on the technical details and findings of their work.