geedge.lantern.io

Techniques

Active probing

detection high

An internal TSG functional-requirements spec ('加密协议JG') defines device support for identifying and blocking ECH, ESNI and QUIC traffic via per-connection SNI/region-matching tables (e.g. DF_QUIC_REGION), plus a companion 'FD报文全流程感知' feature that both passively monitors and actively injects synthetic verification traffic end-to-end through the network path to compute a live per-rule 'CT率' (breakthrough/penetration rate) — the system self-measures how often its own QUIC/ESNI/ECH blocks fail to take effect, and separately throttles logging/blocking detail for rule IDs receiving unusually high hit counts (DF_ATTACK_PROTECTION, 'targeted attack detection').

cn http3-quic-blockesni-eh-blockingrst-injectionactive-probing
detection high

A MESA Lab monthly report states that adjustments to a VPN-detection module accumulated over 10,000 Psiphon3 server IPs and delayed a Psiphon3 client's ability to get online by at least 3 minutes in the researchers' test environment, an earlier-stage data point consistent with the much larger-scale (~70-73K IP) 'vpn-thwarting'/CyberNarrator Psiphon-harvesting pipeline documented elsewhere in this corpus.

cn active-probingip-blocking
evaluation medium

MESA Lab group-meeting notes record parallel R&D on a whitelist-filtering module and a project to fingerprint cloud-hosted circumvention/proxy infrastructure at the IP-block (not single-IP) level, explicitly modeled on 2017/2019 academic 'Bulletproof-hosting IP block' research; the notes also mention local packet captures that found Psiphon IPs, the domain types/ratios Psiphon uses, and active-probing behavior with candidate detection countermeasures.

cn active-probingip-blocking
detection medium

An internal experiment using BurpSuite as a MITM proxy tests injecting a forged QUIC ServerHello carrying a connection-close frame ahead of the real server response, to make the client abandon its QUIC handshake; the author separately proposes recording every site known to support QUIC and simply blocking plain TCP connections to those sites, on the theory that this indirectly forces QUIC off since a censor cannot otherwise tell in advance which TCP flow would have upgraded to QUIC.

cn http3-quic-blockpacket-injectionactive-probing
evaluation high

An internal MESA Lab research survey, '规避工具探测调研' (Circumvention Tool Probing Survey), compiles academic active-probing techniques against Shadowsocks (Frolov, Beznazwy, Cheng/ACER), OpenVPN (Xue et al., USENIX'22 best paper -- RST-threshold fingerprinting), Tor bridges/pluggable transports (Ensafi, Tschantz, Dunna -- cataloguing the GFW's 5 known probe types: TLS/Tor/obfs2/obfs3/SoftEther), and mimicry proxies (StegoTorus fake-HTTP, CensorSpoofer fake-SIP), stating its purpose is 'to evaluate research value and feasibility of application in real projects' -- i.e. assessing which published GFW-active-probing research is worth operationalizing.

cn active-probing
detection medium

A 2018 MESA Lab monthly report describes work on the "GPS"/"先导" (Pioneer) active-probing projects: adding IPv6 scanning support and simultaneous 3-domain scanning to MAAT, alongside active-probing experiments (nslookup/dig/nmap) and root-DNS-server BGP-anycast measurement -- indicating MAAT's rule engine is paired with an active network-scanning subsystem, not purely passive/inline matching.

cn active-probingdpi
detection low

A MESA Lab monthly-report task list includes the next-step item 'design a scheme to identify forged/spoofed SNI in traffic' ([SNI判别]), alongside a separate active/passive traffic-fingerprinting project ('CAM-TEST') that extracts service banners passively and issues active host/port CGI GET probes.

cn sni-blockingactive-probing
detection high

A user manual for a 'Malicious Service IPv6 Address Discovery and Assessment System' documents a sapp application-layer plugin (ipv6_domain.c) that extracts the HTTP Host header, TLS SNI, and DNS AAAA-record domain from live traffic and matches them against a malicious/blocked-domain list to resolve each hit's IPv6 address, alongside a separate active-probing pipeline (ZMapv6 + Entropy/IP-based address-space generation) used to discover IPv6 DNS resolvers and malicious-site IPv6 presence at internet scale.

active-probingdns-poisoning
detection low

The same author (modikai) also authored modikai/cache_prober, a single-commit repo containing dns_prober.go -- naming indicative of a DNS-resolver cache-probing/cache-snooping tool, a reconnaissance technique for inferring which domains a target resolver has recently queried.

active-probing
detection medium

The qiuyuqi/diamondv repo ("DoH探测系统搭建教程" -- "DoH detection system setup tutorial") implements a multi-round active-probing pipeline that performs recursive-DNS/nameserver-side discovery of candidate resolver IPs nationwide, fetches and analyzes their TLS certificates, classifies them by ISP/province, and visualizes results on China/world maps across at least four probing rounds -- an internet-wide active-probing system for discovering DNS-over-HTTPS-capable servers.

active-probing
detection medium

The zhuyujia/diamondv repo (branch "DoH_Scan") documents at least four rounds of systematic DoH-resolver and recursive-DNS-server discovery scans by IIE/MESA-Lab-affiliated researchers, with a companion DNS-probing tool (modikai/dtool: cache/rdns/record probers) and a commit explicitly labeled "upload corresponding egress servers", indicating the same effort also catalogs discovered egress/exit-node infrastructure alongside DNS-resolver reconnaissance.

generic active-probing
evaluation medium

The "diamondv" project runs active internet-wide scans for DoH-capable and recursive DNS servers (dedicated DoH_Scan and rdns_scan branches) and separately catalogs IPv6 addresses discovered via authoritative NS queries, indicating MESA Lab actively maps encrypted-DNS and IPv6 DNS infrastructure.

active-probing
deployment medium

A 2020 MESA Lab monthly report describes building an encrypted-DNS gateway device and a self-hosted DoH server that was wired directly into a live "TSG platform WAN net interface", alongside a passive DoH-service-discovery pipeline that found 39 new DoH-serving domains in a single day of backbone ("科技网") traffic; a related note documents actively probing known DoH-serving IPs' upstream resolvers via a proxy network across 196 countries to check which still function.

generic active-probingdns-poisoning
evaluation high

A 2024 MESA-team-supervised MS thesis ("面向DPI中间件的探测行为检测关键技术研究") builds detection of both measurement-oriented and evasion-oriented probing directed AT DPI middleboxes, using source-IP statistical features, with the stated goal of reducing the middlebox's resource consumption/exposure of characteristics under such probing and preventing DPI-middlebox function failure -- i.e., defensive hardening against exactly the class of academic censorship-measurement and evasion-search techniques (Censored Planet/GFWatch-style probing, Geneva-style automated evasion discovery) cataloged in this lab's own literature survey (see 2026-mesa-censorship-research-survey-f8c349).

generic active-probing
detection high

A 2024 CAS/IIE master's mid-term thesis report, "面向DPI中间件的探测行为识别关键技术研究" (Key Technologies for Identifying Probing Behavior Targeting DPI Middleboxes), builds and evaluates a system that detects and fingerprints active-measurement traffic from OONI, Censored Planet, and GFWatch/GFWeb (via their server-contact patterns, distinct-domain-count thresholds, and response-timing signatures — e.g. flagging a probing srcIP once it queries ≥500-2000 distinct domains at one dstIP), and separately trains a graph-neural-network classifier on raw packet bytes to detect Geneva/SymTCP-style automated censorship-evasion probes, explicitly framed as reducing the DPI middlebox's exposure of its own characteristics to circumvention researchers.

cn active-probingml-classifier
detection medium

The same MESA team overview describes a global "cyberspace mapping" active-reconnaissance platform built on rented distributed cloud nodes worldwide as a rotating probe/proxy pool (unreachable nodes replaced on an ongoing basis), plus an AI-driven (OCR + image recognition) UI-automation framework that can drive Android/iOS apps and web systems from natural-language test scripts for large-scale automated probing and data collection.

generic active-probing
detection high

A published MESA Lab / IIE-CAS paper ("ExitSniffer", CCIS-2021) and two filed patents describe a tool that actively builds 2-hop Tor circuits through every exit relay to decoy websites and diffs the decoy's observed source IP against the relay's public consensus IP to expose non-public "hidden node" infrastructure behind Tor exits (96% coverage of all exits in about 50 seconds), plus a complementary passive method -- a government-funded ("国家信息安全项目") controlled Tor relay that logs real predecessor-hop IPs -- that found hidden nodes behind 71 of 6,850 tracked routing nodes; the same research program's dataset separately logs 10,412,582 real anonymous-user access records against 1,627,920 distinct clearnet domains visited through Tor.

generic active-probingflow-correlation
detection low

An internal encrypted-DNS research report outlines a DoH-server discovery methodology combining public-list lookups, TLS-certificate-based active probing, and an ML-based hybrid active+passive detection method, feeding a global-vs-domestic-network DoH deployment mapping exercise that concludes with a "管控" (control/blocking) recommendations section; the extracted text preserves only section headers/outline, not the underlying methodological detail or numeric findings.

generic active-probing
detection medium

handingkang/fakedns6 implements DNS response spoofing over IPv6, with source under a "ucr.edu" path and a "saddns" binary referencing the academic SAD DNS (Side-channel AttackeD DNS) cache-poisoning technique — evidence MESA Lab is testing/porting the SAD DNS off-path cache-poisoning attack for IPv6, extending classic DNS injection beyond IPv4.

dns-poisoningactive-probing
detection high

A MESA Lab thesis/report states that ESNI/ECH protocol-identification technology, based on TLS extension field type numbers, "has already been applied in actual projects," and lists the researcher's own project participation as "G1系统 - ESNI、ECH加密协议识别" (Feb-Aug 2023) and "G1系统 - QUIC协议旁路ZD" (Feb-Nov 2023, QUIC bypass/blocking), plus a separately implemented "DNS主动探测模块" (DNS active-probing module, marked 已实现/already implemented). "G1" also appears independently as a named legacy system in the Maat/Transformer DPI header (PROTO_VPN comment: "G1历史遗留"), corroborating it as a real internal system name, not a typo.

cn esni-eh-blockingactive-probinghttp3-quic-block
detection low

An internal repo literally named "gfw_test" (single commit, author handle "MDK"/modikai) contains a single Go program named injection_probe.go -- naming strongly indicative of an internal tool for testing GFW-style packet-injection or active-probing behavior, though the extracted material available here is repo/file-tree metadata only, not the source itself.

active-probingpacket-injection
detection high

An internal "网站/应用资源测绘" (website/app resource-mapping) presentation describes active EDNS-Client-Subnet DNS probing from many simulated geographic vantage points to map Google's and Facebook's global service-IP distribution by country/province, a mobile-app pipeline combining UI automation with MITM-proxy/ SSL-pinning-bypass to extract button-to-URL mappings from decrypted app traffic, and a "网站指纹审查" section that explicitly documents domain fronting as an effective evasion of its own DNS/SNI/Host-based website-fingerprint detection, alongside literature-based behavioral/ML website-fingerprinting intended to survive the QUIC/ECH/DoH transition.

sni-blockingactive-probingwebsite-fingerprinttraffic-shape
evaluation high

A censorship-circumvention survey presentation (English-language, apparently used for internal briefing/training on evasion techniques within this ecosystem) explicitly lists Lantern by name, alongside Snowflake, as a circumvention tool discoverable by censors via TLS ClientHello fingerprinting, citing NDSS 2019 "The Use of TLS in Censorship Circumvention," and separately catalogs active- probing techniques (port-scan plus protocol-specific probes) used to discover OpenVPN, probe-resistant proxies (obfs4/shadowsocks/OSSH/MTProto), and traditional VPN servers.

tls-fingerprintactive-probing
deployment high

Under the internal "M22" project (deployment site "YGN-MYTEL" confirms this is Myanmar, at the Mytel carrier), Geedge runs a continuous, individually-tracked signature-extraction pipeline against named commercial VPN apps (Super Unlimited VPN, NotVPN, Avira Phantom, Bitdefender VPN, Thunder VPN, Panda VPN, Mouse VPN, HaloVPN, GoFly VPN, Kiwi/Kuto/Greennet/Gulf Super/Hatunnel+ VPN, and a customer-provided list of 141 more): active probing of app refresh/connect behavior (including automated UI-driving scripts) extracts server IP/FQDN lists, separately for free vs. paid tiers and Android vs. iOS, which are then loaded as blocklist objects and validated against a false-positive ("CT"/穿透) test pass in a separate demo environment before deployment.

mm ip-blockingactive-probing
evaluation medium

A MESA Lab student research report catalogs the GFW's known Shadowsocks-detection methodology (passive detection via first-packet length/entropy; active probing triggered after as few as 13 legitimate client connections, typically within seconds of the first legitimate connection) alongside six published ML-based Shadowsocks traffic-classification techniques (a packet-size-image CNN at >98% accuracy, random-forest on flow/host/DNS-behavior features, PCA-Pearson feature selection), compiled as apparent background research for in-house detection work.

cn traffic-shapeml-classifieractive-probing
detection medium

handingkang/ohmydns2 is a CoreDNS-fork DNS server built by a MESA Lab/IIE engineer ([email protected]) that bundles a "prober" active-probing plugin, a "v64dns" module, and an "atk" plugin with dedicated branches (atk_DDoS, atk_DDoS_resolver, atk_qp) implementing DNS response amplification and an attempted DNS injection/tampering feature ("注入篡改功能实现尝试"). This combines active DNS probing with resolver-based amplification/attack tooling in one codebase.

cn active-probingdns-poisoning
detection medium

handingkang/ohxmap is an internal MESA Lab build of the XMap-family Internet-scale scanner, with extensive IPv6 DNS probe-generation modules (module_dns6a/dns6ae/dns6af/dns6x etc.) and custom Redis output modules; it is maintained by the same author (韩丁康/HDK, [email protected]) responsible for the DoH/recursive-DNS discovery campaigns in the diamondv repo, corroborating an internal large-scale IPv6 address-space/DNS reconnaissance capability.

generic active-probing
detection high

Project "M22" runs a standing weekly program to extract and patch detection signatures against "Turbo VPN": automated dial-testing continuously discovers server IPs (tens to hundreds/week), each batch packaged into a dated JSON patch file, validated for both blocking efficacy and false-positive risk before rollout. Ran continuously Aug-Nov 2024 in the source ticket.

mm active-probingdpi
detection medium

The same M22 weekly-extraction program runs in parallel against "7VPN": automated dial-tests repeatedly found its free-tier nodes already non-functional/blocked across weekly checks Aug-Oct 2024, indicating sustained monitoring even absent a signature update.

mm active-probing
detection high

M22 runs a large-scale automated pipeline against numerous commercial VPN apps: APK decompilation + HTTPS-proxy interception to extract servers/FQDNs, automated dial-testing at volume (one app: 17,554 dial-tests, 4,073 servers discovered, 94% 24-hour block rate), and OpenCV-based automated ad-dismissal to keep test automation running unattended.

mm dpiactive-probingip-blocking
detection medium

A repo under a "PanGu" (盘古) namespace, "t2httpcontentscanner" (component T2_HTTP_DIG_BIZ, i.e. an HTTP-layer inspection/scanning business module), bundles an HTTP content-scanning DPI plugin together with a packet-injection header (stream_inject.h); its final 2019 commit updates both a third-party "丁牛" (Dingniu) dynamic library dependency and a "主动测试脚本" (active-probing/active-test script), indicating active-probing tooling shipped alongside this HTTP scanning+injection module. This appears to be a separate or predecessor DPI line from the sapp/MAAT stack documented elsewhere in this corpus.

generic dpiactive-probingpacket-injection
detection medium

An internal Go tool named 'prober' (handingkang/prober, from the same author as a separate 'alias_prefix' detection script) implements packet-sending ('发包') functionality and a 'test ingress/egress correlation' ('测试出入口关联') feature -- an active-probing capability for testing whether traffic entering and exiting a network point can be correlated, consistent with GFW-style active probing of candidate circumvention servers.

active-probing
evaluation medium

The same student's prior (October 2022) monthly report documents an Alibaba-Cloud-hosted full-IPv4 scan that found 5.5 million hosts with an open RDP port (3389), performed as part of thesis research into improving RDP man-in-the-middle detection methodology.

cn active-probing
detection high

A MESA engineer wrote a SAPP business-layer plugin (v1 shipped to GitLab) that fingerprints network scanning/probing tools, producing a "scanning/probing tool fingerprint-database construction report." The companion fingerprint report documents Nmap's default host-discovery probe sequence (ICMP echo request, TCP SYN to port 443, TCP ACK to port 80, ICMP timestamp request) captured against a live target.

generic active-probing
detection high

MESA Lab / IIE-CAS research (patent application no. 202410203156.3, "一种基于主动探测的Tor桥节点的隐藏节点发现方法及系统") built automated active-probing tooling that discovered 44 "ShadowBridge" instances and 71 hidden real-IP nodes behind public Tor bridges over a 3-month run, finding this hidden-node churn increased the count of ASes able to eavesdrop on bridge traffic by roughly 30.8%; the same effort built an automated bridge-collection pipeline (proxied Gmail-based bridge requests plus manual enumeration, ~8000 bridge addresses collected) and a private Tor test range including private obfs4 and meek bridge deployments.

generic active-probing
detection medium

A MESA Lab monthly work report (research group under Fangyu Xing / 方滨兴) states the researcher completed a study of active probing against Shadowsocks and produced an initial reproduction of probe generation targeting historical Shadowsocks server versions, alongside two finished commercial-VPN analysis reports, with further probe-generation work and a connection between state fuzzing and active probing planned as next steps.

cn active-probing
evaluation low

A MESA Lab monthly report describes functional testing of a "TSG DoH proxy" (TSG DoH代理) covering availability, HTTP version support, server-side behavior, and HTTP header fields, with results posted to the internal Confluence wiki (docs.mesalab.cn), under a project labeled XDC. The same reporting period covers a separate autoencoder-based DoH-traffic-detection paper with an "improved active-verification method" for discovering additional DoH resolvers.

cn active-probing
detection medium

A 2024 bachelor's thesis from UCAS, advised by a senior engineer at the Institute of Information Engineering (IIE), Chinese Academy of Sciences, built and evaluated a dynamic, iterative VPN-server identification prototype combining active-probing response features with passive traffic features and an IP-similarity graph-relationship model; the combined system reached 92.44% online-test identification accuracy (versus 87.19% accuracy / 86.38% F1 for the offline active-probing-only variant).

generic active-probing
detection high

A CAS-institute master's thesis ("基于IP相似性分析的VPN服务识别技术研究") builds a VPN-server-identification system combining active TCP/UDP port probing (SYN scan on ports 1194 OpenVPN, 500/4500 IPSec, 1701 L2TP, 22, 443, 51820 WireGuard, 992, 4090, 655; UDP scan on 80/53/25/465/110/143/389/21/3389/445/69/3306/6379) with passive-traffic "IP similarity" graph analysis, reaching 92.44% online-test accuracy and supporting dynamic feature-library updates as services change.

active-probingml-classifiertraffic-shape
detection medium

Three harvested datasets catalog full server-fleet inventories for multiple commercial VPN/proxy brands -- WaselPro/BVPN/SmokeTunnel/iWasel/BackboneVPN (with per-node CA certificate, IPsec PSK, and SSH private key captured), VyprVPN/GoldenFrog (per-location hostname/IP/coordinates), and tap2free (per-node IP with PRO/FREE tier flags) -- i.e. Geedge enumerates and archives entire commercial VPN provider bootstrap/config responses, not just individually observed connections.

active-probingip-blocking
detection medium

Two versions of an academic active-probing VPN-server-detection paper ("VPNChecker"/"VPNSniffer", WWW'24) held in this corpus specifically profile Psiphon3: Psiphon3 servers account for the single largest share (6.64%) of labeled VPN servers in the authors' ISP dataset, most respond to an OpenVPN probe by silently timing out rather than returning the standard OpenVPN response (a "probe-resistant" behavior the paper explicitly attributes to Psiphon3), and Psiphon3 servers share a small number of characteristic "Probing Port Combinations" (e.g. {443,53,22}, {443,554,22}) across the vendor's fleet that the paper's graph-based classifier uses to link servers together.

cn active-probingml-classifier
detection high

The same M22-tagged VPN-finder plugin set implements active UDP probing to elicit and harvest server IP addresses from CyberGhost VPN's protocol behavior, and separately fingerprints Windscribe VPN via TLS certificate features — two distinct active-probing/fingerprinting techniques feeding the same central VPN-blocklist knowledge base, with an explicit configurable active-scan packet rate.

mm active-probingtls-fingerprint
detection high

The "intelligence-learning-engine/vpn-finder-plugins" repo was initialized specifically for the M22 (Myanmar) deployment ("Init: M22初始化", branches "24.08_M22"/"tsg24.02_M22") and implements per-service detection plugins for at least nine commercial VPN products (CyberGhost, ProtonVPN, TurboVPN, Windscribe, IPVanish, Ivacy, VPN Unlimited, GeckoVPN, Hotspot Shield) plus Psiphon3, feeding discovered server identifiers into a central "knowledge base" that field deployments sync from on their own release cadence.

mm active-probing
detection high

An internal talk deconstructing MESA Lab's own WWW2024 paper "Identifying VPN Servers through Graph-Represented Behaviors" (VPNTracker) confirms it was built on the group's own internal production log data ("组内数据"), and details its core active-probing feature: "Stealth Ports" (TCP ports observed open in passive traffic that refuse/ignore active probes) combined with vendor-specific patterns in the error responses VPN servers return to out-of-protocol active probes (e.g. a DNS query sent to the port), fed into a graph neural network over client-IP/server-IP/port relationships; framed explicitly as anti-geo-fraud tooling against services like ChatGPT, Netflix, and NetEase Cloud Music.

cn active-probingml-classifier
detection medium

TSG's galaxy-job scheduler runs a 'Web Sketch' domain-probing task (given a sharded mode explicitly to support large-scale parallel probing across servers) and a 'CN' knowledge-base sync pipeline (JIRA ticket prefix CN-, matching this corpus's CyberNarrator codename) that supports encrypting sensitive knowledge-base files and periodically updates a dark-web-indicator table (ioc_darkweb) -- evidence that CyberNarrator's blocklist/knowledge-base pipeline includes an active domain-probing component and a dark-web IOC feed, beyond the previously-documented Psiphon3 IP-harvesting and Pakistan subscriber-correlation components.

active-probing
evaluation medium

A MESA Lab research note dissects the Tor Project's webtunnel pluggable transport (HTTPT-based) and reports a hands-on pcap analysis of 3 public webtunnel bridges: the observed TLS ClientHello/cipher-suite fingerprint and SNI matched an ordinary HTTPS connection to the bridge's cover domain, with no certificate visible in the captured handshake -- i.e. these deployments withstood the lab's basic passive TLS-layer fingerprinting attempt at the time of writing.

generic tls-fingerprintactive-probing
detection high

A dial-testing ('拨测') log documents systematic active-probing/reachability testing from a 'YGN-GTG' (Yangon Gateway, Myanmar) network node against six overseas test sites in Singapore, France, the US, New Zealand, South Africa, and Chile, using packet capture plus flow statistics to quantify one-way vs two-way flow completion (0-45%% flow loss observed per site) through gateway node IPs 'YGN-GTG: 10.173.12.x' -- direct empirical evidence of connectivity/blocking-effectiveness QA testing tied to the Myanmar (M22) Yangon deployment, run against an 'NCSC'-provided 'Campana' test WiFi network.

mm active-probing
detection high

A MESA Lab repo (shihaoyue/yy_deploy_script) contains an organized suite of active attack tooling specifically targeting encrypted DNS: DoH/DoT downgrade attacks, DoH/DoT DDoS including a CVE-2024-4487 (HTTP/2 Rapid Reset) exploit script, IPv6 DNS response spoofing/injection (fakedns6 using forged-source-address "saddns"), a DNSSEC-downgrade proxy, DNSSEC-DDoS tooling, and an active DNS-fingerprinting probe pair (fpdns_client/fpdns_server under a folder named "TargetGZ"). This is direct evidence of GFW-adjacent R&D that specifically attacks the encrypted-DNS protocols (DoH/DoT) circumvention tools often rely on for resolver privacy.

cn dns-poisoningpacket-injectionactive-probing
detection medium

A MESA researcher's status report lists work on encrypted-DNS-resolver role classification (ADNS/FDNS/RDNS) and DoH resolver component-chaining clustering, alongside a project named "YYDNS" (probing-system backend workflow and data integration) and a completed "ZX VPN active-probing requirement discussion" -- indicating a dedicated active-probing module was scoped against a specific named VPN product.

generic active-probing
detection medium

MESA Lab operates a distributed active-probing system internally called "YYDNS" (backend repos handingkang/yserver and handingkang/yyserver, frontend repo zhuyujia/yydns_vue, all sharing a "YYDNS 库表关系设计.pdf" design doc). Agents perform TCP ping/latency measurement against "targets" ("参与探测的节点信息", "状态感知"/state-sensing), and the Vue frontend's icon set uses literal Tor role terminology (guard.svg, relay.svg, onion.svg, torInfo.svg, client.svg), indicating the system is built to track and classify Tor guard/relay nodes specifically. One deployment instance (yyserver, 2023) stores probe-target geolocation data heavily concentrated in coordinates matching Taiwan (lat ~22.6-25.1N, lon ~119.5-121.7E).

active-probing