Tor (onion routing)
An exported IP-blocklist object with the literal header format 'IP[Single||/CIDR||-Range]#[Port]' and 5,511 entries, each a single IP with port range 0-65535 (i.e. full-IP block regardless of port), includes 185.220.101.77 — an address in the 185.220.101.0/24 block long associated with Tor exit-relay operators — suggesting at least part of this object targets Tor exit infrastructure by IP rather than by protocol fingerprint.
An internal MESA Lab research survey, '规避工具探测调研' (Circumvention Tool Probing Survey), compiles academic active-probing techniques against Shadowsocks (Frolov, Beznazwy, Cheng/ACER), OpenVPN (Xue et al., USENIX'22 best paper -- RST-threshold fingerprinting), Tor bridges/pluggable transports (Ensafi, Tschantz, Dunna -- cataloguing the GFW's 5 known probe types: TLS/Tor/obfs2/obfs3/SoftEther), and mimicry proxies (StegoTorus fake-HTTP, CensorSpoofer fake-SIP), stating its purpose is 'to evaluate research value and feasibility of application in real projects' -- i.e. assessing which published GFW-active-probing research is worth operationalizing.
Geedge runs an explicit, named signature-extraction program specifically targeting circumvention tools — Freegate, Psiphon, Ultrasurf, and Tor Browser (by package name: com.golden.freegate, com.psiphon3.subscription, us.ultrasurf.mobile.ultrasurf, org.torproject.torbrowser) — across Android/iOS/Windows, with weekly signature updates, for a site internally called 'K project'.
A published MESA Lab / IIE-CAS paper ("ExitSniffer", CCIS-2021) and two filed patents describe a tool that actively builds 2-hop Tor circuits through every exit relay to decoy websites and diffs the decoy's observed source IP against the relay's public consensus IP to expose non-public "hidden node" infrastructure behind Tor exits (96% coverage of all exits in about 50 seconds), plus a complementary passive method -- a government-funded ("国家信息安全项目") controlled Tor relay that logs real predecessor-hop IPs -- that found hidden nodes behind 71 of 6,850 tracked routing nodes; the same research program's dataset separately logs 10,412,582 real anonymous-user access records against 1,627,920 distinct clearnet domains visited through Tor.
A June 2024 MESA Lab internal survey ("针对审查系统的科学研究及探测技术调研报告") explicitly states its purpose is to catalog academic/public censorship-measurement and circumvention research (OONI, Augur, Satellite, GFWatch, Citizen Lab, CensorBib, FOCI/IMC/NDSS/CCS/USENIX Security papers) in order to find and patch GFW/censorship-system vulnerabilities before outside researchers exploit them. It systematically covers circumvention protocols/tools (Shadowsocks, VMess, Trojan, decoy routing, Parrot-style mimicry, CovertCast, Slitheen++, ESNI/ECH, uTLS) and notes GFW blocked ESNI (not ECH) since July 2020, plus historical TLS-fingerprint blocking of meek by a Cyberoam firewall (2016).
MESA Lab maintains a dedicated "obfs4验证" (obfs4 verification) tool repo (wangmeiqi/obfs4_verify) containing Go and Python obfs4-handshake test/verify scripts plus a bundled pyelligator (Elligator2) implementation — the elliptic-curve-point-indistinguishability library obfs4 itself relies on for its uniform-random handshake — indicating active work to validate, detect, or replicate Tor's obfs4 pluggable-transport handshake.
TSG's 'APP' classification feature has named, purpose-built signatures for specific circumvention tools — the ticket explicitly configures active-client-IP tracking for the APP categories Freegate, Psiphon3, and Tor.
Geedge runs standing weekly signature-extraction assignments specifically against Freegate, Psiphon, Ultrasurf, and Tor Browser (by Play Store package name) across at least two projects, each with a dedicated engineer, spanning Android/iOS/Windows.
Signature extraction for named circumvention tools (Freegate, Psiphon, Ultrasurf, Tor Browser) explicitly captures QUIC SNI alongside TLS SNI and HTTP Host header, confirming TSG's fingerprinting pipeline covers QUIC transport, not just TCP/TLS.
Myanmar deployment (M22) systematically reverse-engineered and blocked Orbot (Tor's official Android client) and ProtonMail, alongside numerous consumer VPN apps, via the AppSketch feature-extraction pipeline. Orbot: 287 server IPs extracted across multi-hop nodes, one connection mode fully blocked. ProtonMail: mail server IPs/FQDNs extracted, blocking verified as full service denial (cannot send, receive, download attachments, or create a new account) on Android and iOS.
MESA Lab / IIE-CAS research (patent application no. 202410203156.3, "一种基于主动探测的Tor桥节点的隐藏节点发现方法及系统") built automated active-probing tooling that discovered 44 "ShadowBridge" instances and 71 hidden real-IP nodes behind public Tor bridges over a 3-month run, finding this hidden-node churn increased the count of ASes able to eavesdrop on bridge traffic by roughly 30.8%; the same effort built an automated bridge-collection pipeline (proxied Gmail-based bridge requests plus manual enumeration, ~8000 bridge addresses collected) and a private Tor test range including private obfs4 and meek bridge deployments.
MESA Lab operates an internal Tor "cyber range" (靶场) that builds and deploys custom Docker images running a modified Tor codebase across directory-authority, relay, guard, exit, client, and onion-service roles for hands-on experiments; this doc walks through forcing the deprecated Tor v2 onion-service protocol back on for a specific "v2 hidden service discovery" exercise.
Peer-review correspondence on the companion PhD thesis ('Tor隐藏服务溯源管控关键技术研究', same MESA Lab body of work as the AlterCell report) documents a third technique -- a descriptor-cache-overflow-based denial-of-service that drove a target hidden service's accessibility down by 90% in real Tor network testing at low, sustained cost -- and shows a reviewer explicitly flagging the thesis for undisclosed state-security sensitivity and instructing the author to replace the original '管控' (state control/management) framing with the more academic 'denial of service' term, while the thesis's own stated motivation is '维护国家网络安全和社会稳定' (safeguarding national cybersecurity and social stability).
A MESA Lab research note dissects the Tor Project's webtunnel pluggable transport (HTTPT-based) and reports a hands-on pcap analysis of 3 public webtunnel bridges: the observed TLS ClientHello/cipher-suite fingerprint and SNI matched an ordinary HTTPS connection to the bridge's cover domain, with no certificate visible in the captured handshake -- i.e. these deployments withstood the lab's basic passive TLS-layer fingerprinting attempt at the time of writing.
MESA Lab operates a distributed active-probing system internally called "YYDNS" (backend repos handingkang/yserver and handingkang/yyserver, frontend repo zhuyujia/yydns_vue, all sharing a "YYDNS 库表关系设计.pdf" design doc). Agents perform TCP ping/latency measurement against "targets" ("参与探测的节点信息", "状态感知"/state-sensing), and the Vue frontend's icon set uses literal Tor role terminology (guard.svg, relay.svg, onion.svg, torInfo.svg, client.svg), indicating the system is built to track and classify Tor guard/relay nodes specifically. One deployment instance (yyserver, 2023) stores probe-target geolocation data heavily concentrated in coordinates matching Taiwan (lat ~22.6-25.1N, lon ~119.5-121.7E).