Posts

Technical Analysis of the Geedge Networks Firewall Source Code Leak

· The authors

Our USENIX Security '26 paper: what we found in the leaked source code of Geedge Networks' censorship firewall, and how we tested for it in the wild.

35th USENIX Security Symposium (USENIX Security '26)

Anna Ablove1, Johnnie Walker2, Ben Wolin1, Niklas Niere3, Felix Lange3, Aaron Ortwein1, Armin Huremagic1, Richa Priyanka1, Ali Zohaib4, Jade Sheffey4, Nico Heitmann3, J. Alex Halderman1, Juraj Somorovsky3, Amir Houmansadr4, Roya Ensafi1, Mingshi Wu2, Eric Wustrow5

1 University of Michigan  ·  2 GFW Report  ·  3 Paderborn University  ·  4 University of Massachusetts Amherst  ·  5 University of Colorado Boulder

Artifact EvaluatedArtifacts Available Open Science

Abstract

In September 2025, over 100K internal documents (including code, communications, etc.) from Geedge Networks, a Chinese DPI company with ties to the Great Firewall of China, were leaked to the public. In this paper, we analyze the source code from this leak, focusing on Geedge Networks' flagship product, the Tiangou Secure Gateway (TSG) firewall. Working across multiple repositories, we successfully build and run a local copy of TSG—revealing key aspects of its architecture, including the protocols it is capable of parsing and the format of blocking rules used to censor sites, proxies, and other protocols. Finally, we extract several fingerprints from TSG, including custom random number generators and parsing idiosyncrasies that allow us to identify its use and similar deployments in the Great Firewall of China.

This is the first time that the source code of a commercial DPI has been leaked, and our work is the first code analysis of a core firewall component used in national censorship infrastructure. This unprecedented investigation offers insights that can assist circumvention developers and Internet security researchers in further understanding the capabilities and limitations of modern censorship technology.

What we found

The paper, section by section

These pages carry the technical content of the paper for readers who want the findings without the PDF.

What was in the leak

The company was founded in 2018 by Fang Binxing, colloquially known as the "Father of the GFW" for his foundational role in designing the Great Firewall. Geedge also maintains a close collaborative relationship with the Massive and Effective Stream Analysis (MESA) Lab at the Chinese Academy of Sciences, whose academic research on traffic analysis directly informs product development.

CategoryArtifactSizeKey contents
Source codemirror/repo.tar463.0 GiBRPM bundles: Firewall, libcbd, QDPI and Glimpse detectors
Source codemesalab_git.tar.zst59.4 GiBGit repos: SAPP, Protocol Plugins, Stellar-on-SAPP, Stellar, Maat, tsg-os-buildimage
Confluence2 archives46.4 GiBVPN signature logs, Psiphon collateral-damage analysis
Jirageedge_jira.tar.zst2.5 GiBDeployment tickets (Myanmar, Ethiopia), bug fixes
Other14 files + filelist10.7 MiB

Composition of the 572 GiB Geedge Networks data leak. Note: SAPP and the protocol plugins are additionally packaged in RPM bundles in repo.tar.

Civil society investigations have highlighted evidence of deployments of Geedge Networks' products across multiple countries, including Kazakhstan (code-named K18/K24), Ethiopia (E21), Pakistan (P19), and Myanmar (M22), and describe the company's role as extending beyond software provision to encompass system integration, operator training, and ongoing technical support. See Resources for that reporting.

Artifact and data

Our result files, anonymized PCAPs, scanning scripts, and measurement tools are archived on Zenodo. This includes the TLS length-field scanner and results, QUIC version probes, IP fragmentation reassembly PCAPs, DNS injection behavior data, and the TCP RST injection fingerprinting tool. See Resources for the full contents.

Cite this work

Please cite the USENIX Security '26 version. A copy of the camera-ready paper is available here.

@inproceedings{ablove2026geedge,
  title     = {Technical Analysis of the Geedge Networks Firewall Source Code Leak},
  author    = {Ablove, Anna and Walker, Johnnie and Wolin, Ben and Niere, Niklas and
               Lange, Felix and Ortwein, Aaron and Huremagic, Armin and Priyanka, Richa and
               Zohaib, Ali and Sheffey, Jade and Heitmann, Nico and Halderman, J. Alex and
               Somorovsky, Juraj and Houmansadr, Amir and Ensafi, Roya and Wu, Mingshi and
               Wustrow, Eric},
  booktitle = {35th USENIX Security Symposium (USENIX Security 26)},
  year      = {2026},
  publisher = {USENIX Association}
}