geedge.lantern.io
deployment confidence: high public

Weekly "新疆移动流量分析报告" (Xinjiang Mobile Traffic Analysis Report) and "新疆联通流量分析报告" (Xinjiang Unicom Traffic Analysis Report) documents, produced by an internal "运营商前端分析团队" (Carrier Frontend Analysis Team) and spanning January-July 2023, give carrier-level domestic deployment scale for Xinjiang: China Mobile Xinjiang alone reports 4.4 Tbps total bandwidth / 1 Tbps access bandwidth, with weekly throughput up to 22.73 PB and rate peaks over 580 Gbps. Both reports include a dedicated "国外APP应用概况" (foreign app overview) section enumerating server IP/location for ~29 named foreign platforms (BBC, Discord, Facebook, Gmail, Google, Instagram, Netflix, Reddit, Skype, Telegram, Twitter, Whatsapp, Youtube, Zoom, etc.) alongside domestic app traffic, directly corroborating the taxonomy's Xinjiang domestic-deployment note at the level of two named carriers with concrete recurring cadence.

新疆移动总带宽为4.4Tbps,接入带宽1Tbps ... 6月26日至7月2日期间,新疆移动前端吞吐量共计22.73PB ... 4. 国外APP应用概况 17 / 4.1 国外常用APP 服务端IP 和位置 18 / 4.1.21 Telegram 29 / 4.1.26 Whatsapp 32
censorscn
productstsg
capabilitydeployment-config

extracted_by: claude-sonnet-5 · added 2026-08-26 · id: 2026-xinjiang-carrier-reports-ac

Related findings

deployment

An internal TSG operations/troubleshooting manual lays out TSG's full traffic pipeline (NIC -> mrzcpd/marsio capture driver -> sapp DPI engine -> firewall/proxy(KNI->TFE)/active-defense/WAN-NAT policy branches) and shows engineers using maat_redis_tool to pull the live Redis-synced blocking policy tables (TSG_SECURITY_COMPILE, TSG_OBJ_IP_ADDR, TSG_OBJ_APP_ID) and filter them by numeric policy/object ID to debug why a block rule isn't firing.

detection

The internal 'MAAT网络流处理配置统一描述框架' engineering manual (v3.1.20, author 郑超, 2021) documents MAAT's Redis-synced rule-compilation framework and its RuleScan/Hyperscan-based pattern-matching engine (libmaatframe.so / librulescan), and records that RuleScan's fast-scan feature caused a production outage on 2019-03-19 and has been disabled ever since.

detection

An internal TSG functional-requirements spec ('加密协议JG') defines device support for identifying and blocking ECH, ESNI and QUIC traffic via per-connection SNI/region-matching tables (e.g. DF_QUIC_REGION), plus a companion 'FD报文全流程感知' feature that both passively monitors and actively injects synthetic verification traffic end-to-end through the network path to compute a live per-rule 'CT率' (breakthrough/penetration rate) — the system self-measures how often its own QUIC/ESNI/ECH blocks fail to take effect, and separately throttles logging/blocking detail for rule IDs receiving unusually high hit counts (DF_ATTACK_PROTECTION, 'targeted attack detection').

detection

Raw structured DNS event logs (dated 2021-08-23) captured from what appears to be a GFW-adjacent DNS monitoring/injection pipeline use a schema purpose-built for DNS response forgery ('CHEAT_TYPE', 'CHEAT_RCODE', 'CHEAT_STRATEGY', 'CHEAT_RR', 'INJECTED_PKT_FILE' fields) alongside per-query geolocation; sampled records show lookups for facebook.com and tiktokv.com originating from residential China Telecom/Unicom/Mobile subscriber IPs in Guangdong, Zhejiang, Anhui and other provinces, resolving against both domestic and foreign (8.8.8.8, OpenDNS) resolvers.

deployment

A 2023 MESA Lab monthly report describes the 'TF' project's active-defense work: test cases for serial ('串联') HTTP hijack/tamper and parallel ('并联') DNS race-injection ('DNS抢答'), performance tuning that scaled active-defense capacity from 3 to 5 units, converting two existing TSG boxes to active-defense mode, and rewriting the active-defense flow-control logic to no longer depend on sapp.

deployment

A recurring Chinese-language daily '出入口整体流量监测报告' (Entry/Exit Overall Traffic Monitoring Report), sampled here from June 2022 through Feb 2024, tracks national-gateway-scale traffic (peak 1.1 Tbps, 5.62 PB/day in one instance; top apps by volume include Bytedance, Tencent, Kuaishou, Alibaba, Baidu). The 2024-01-16 instance explicitly discloses that of 34 total ingress/egress links (2.68 Tbps aggregate capacity), the monitoring system actually taps only 2 links (200 Gbps) — 7.46% of total link capacity — meaning the reported traffic figures reflect partial-link sampling, not full-link coverage.