geedge.lantern.io
deployment confidence: high public

At least 33 additional recurring reports in this batch ("IDC阿里服务质量监测报告" / IDC Alibaba Service-Quality Monitoring Report, "IDC字节跳动服务质量监测报告" / IDC ByteDance Service-Quality Monitoring Report, and "IDC整体流量监测报告" / IDC Overall Traffic Monitoring Report, plus further variant-named "出入口" ingress/egress reports not individually cited here) span 2022-06 through 2024-02 and show monitoring deployed inline/mirrored at major domestic hyperscaler IDC interconnects — 10 to 22 links, 1 to 1.21 Tbps of aggregate bandwidth — for both Alibaba and ByteDance specifically, indicating the deployment footprint extends beyond telecom carriers (Xinjiang Mobile/Unicom) to major domestic cloud/CDN providers' peering links.

IDC阿里服务质量监测报告 2024-02-07 ... IDC链路共计10条,总带宽1Tbps(10*100Gbps);系统实际接入链路10条,接入带宽1Tbps(10*100Gbps)。实际接入带宽为总带宽的100%。 ... IDC字节跳动服务质量监测报告 ... IDC链路共计22条,总带宽1.21Tbps(11*100Gbps、11*10Gbps)
censorscn
productstsg
capabilitydeployment-config

extracted_by: claude-sonnet-5 · added 2026-08-26 · id: 2026-idc-hyperscaler-monitoring-ac

Related findings

deployment

An internal TSG operations/troubleshooting manual lays out TSG's full traffic pipeline (NIC -> mrzcpd/marsio capture driver -> sapp DPI engine -> firewall/proxy(KNI->TFE)/active-defense/WAN-NAT policy branches) and shows engineers using maat_redis_tool to pull the live Redis-synced blocking policy tables (TSG_SECURITY_COMPILE, TSG_OBJ_IP_ADDR, TSG_OBJ_APP_ID) and filter them by numeric policy/object ID to debug why a block rule isn't firing.

detection

The internal 'MAAT网络流处理配置统一描述框架' engineering manual (v3.1.20, author 郑超, 2021) documents MAAT's Redis-synced rule-compilation framework and its RuleScan/Hyperscan-based pattern-matching engine (libmaatframe.so / librulescan), and records that RuleScan's fast-scan feature caused a production outage on 2019-03-19 and has been disabled ever since.

detection

An internal TSG functional-requirements spec ('加密协议JG') defines device support for identifying and blocking ECH, ESNI and QUIC traffic via per-connection SNI/region-matching tables (e.g. DF_QUIC_REGION), plus a companion 'FD报文全流程感知' feature that both passively monitors and actively injects synthetic verification traffic end-to-end through the network path to compute a live per-rule 'CT率' (breakthrough/penetration rate) — the system self-measures how often its own QUIC/ESNI/ECH blocks fail to take effect, and separately throttles logging/blocking detail for rule IDs receiving unusually high hit counts (DF_ATTACK_PROTECTION, 'targeted attack detection').

detection

Raw structured DNS event logs (dated 2021-08-23) captured from what appears to be a GFW-adjacent DNS monitoring/injection pipeline use a schema purpose-built for DNS response forgery ('CHEAT_TYPE', 'CHEAT_RCODE', 'CHEAT_STRATEGY', 'CHEAT_RR', 'INJECTED_PKT_FILE' fields) alongside per-query geolocation; sampled records show lookups for facebook.com and tiktokv.com originating from residential China Telecom/Unicom/Mobile subscriber IPs in Guangdong, Zhejiang, Anhui and other provinces, resolving against both domestic and foreign (8.8.8.8, OpenDNS) resolvers.

deployment

A 2023 MESA Lab monthly report describes the 'TF' project's active-defense work: test cases for serial ('串联') HTTP hijack/tamper and parallel ('并联') DNS race-injection ('DNS抢答'), performance tuning that scaled active-defense capacity from 3 to 5 units, converting two existing TSG boxes to active-defense mode, and rewriting the active-defense flow-control logic to no longer depend on sapp.

deployment

A recurring Chinese-language daily '出入口整体流量监测报告' (Entry/Exit Overall Traffic Monitoring Report), sampled here from June 2022 through Feb 2024, tracks national-gateway-scale traffic (peak 1.1 Tbps, 5.62 PB/day in one instance; top apps by volume include Bytedance, Tencent, Kuaishou, Alibaba, Baidu). The 2024-01-16 instance explicitly discloses that of 34 total ingress/egress links (2.68 Tbps aggregate capacity), the monitoring system actually taps only 2 links (200 Gbps) — 7.46% of total link capacity — meaning the reported traffic figures reflect partial-link sampling, not full-link coverage.