communication in a manner that could plausibly be explained by errant technical failures or other random network effects. In the following sections, we define the three different generations of cyberspace controls and provide examples for each from our research
in the CIS region. The three generations of controls are also summarized in Table 2.4.
First-Generation Controls
First-generation controls focus on denying access to specific Internet resources by
directly blocking access to servers, domains, keywords, and IP addresses. This type of
filtering is typically achieved by the use of specialized software or by implementing
instructions manually into routers at key Internet choke points. First-generation filtering is found throughout the world, in particular among authoritarian countries, and is
the phenomenon targeted for monitoring by the ONI’s methodology. In some countries, compliance with first-generation filtering is checked manually by security forces,
who physically police cybercafe ´s and ISPs.
In the CIS, first-generation controls are practiced on a wide scale only in Uzbekistan
and Turkmenistan. In Uzbekistan, a special department of the SNB (KGB) monitors the
Internet and develops block lists that are then conveyed to individual ISPs who in turn
implement blocking against the specific resources or domain names. The filtering is
universal across all ISPs, and the SNB spot-checks ISPs for compliance. In Turkmenistan, filtering is centralized on the country’s sole ISP (operated by Turkmentelekom),
and access is heavily filtered. Up until late 2007, Internet access in Turkmenistan was
severely restricted and expensive, limiting its access and impact.
Table 2.3
SUMMARY RESULTS FOR ONI TESTING FOR INTERNET FILTERING, 2007–2008
No Evidence
Suspected
Selective
Substantial
Pervasive
Armenia
Azerbaijan
Belarus
Georgia
Kazakhstan
Kyrgyzstan
Moldova
Tajikistan
Turkmenistan
Russia
Ukraine
Uzbekistan
22
Ronald Deibert and Rafal Rohozinski
in the CIS region. The three generations of controls are also summarized in Table 2.4.
First-Generation Controls
First-generation controls focus on denying access to specific Internet resources by
directly blocking access to servers, domains, keywords, and IP addresses. This type of
filtering is typically achieved by the use of specialized software or by implementing
instructions manually into routers at key Internet choke points. First-generation filtering is found throughout the world, in particular among authoritarian countries, and is
the phenomenon targeted for monitoring by the ONI’s methodology. In some countries, compliance with first-generation filtering is checked manually by security forces,
who physically police cybercafe ´s and ISPs.
In the CIS, first-generation controls are practiced on a wide scale only in Uzbekistan
and Turkmenistan. In Uzbekistan, a special department of the SNB (KGB) monitors the
Internet and develops block lists that are then conveyed to individual ISPs who in turn
implement blocking against the specific resources or domain names. The filtering is
universal across all ISPs, and the SNB spot-checks ISPs for compliance. In Turkmenistan, filtering is centralized on the country’s sole ISP (operated by Turkmentelekom),
and access is heavily filtered. Up until late 2007, Internet access in Turkmenistan was
severely restricted and expensive, limiting its access and impact.
Table 2.3
SUMMARY RESULTS FOR ONI TESTING FOR INTERNET FILTERING, 2007–2008
No Evidence
Suspected
Selective
Substantial
Pervasive
Armenia
Azerbaijan
Belarus
Georgia
Kazakhstan
Kyrgyzstan
Moldova
Tajikistan
Turkmenistan
Russia
Ukraine
Uzbekistan
22
Ronald Deibert and Rafal Rohozinski
