Blocking tor at the firewall level isn't difficult. Anything with packet inspection can do it.
Edit: I've looked into this some more and you're kinda right. It's SSL and with very little to give it away except talking to exit nodes. Most of the systems I'm looking at are just discerning it from IP, the few exceptions require SSL MITM, which I also wouldn't put by the government.