readily available. Depending on the network infrastructure within the country it may also be
possible to block at or near the international gateways so that the blocking is uniform across
ISPs.
Countries new to filtering will generally start with IP blocking before moving on to more expensive filtering solutions. ISPs most often respond quickly and effectively to blocking orders
from the government or national security and intelligence services. Therefore they block what
is requested in the cheapest way using technology already integrated into their normal network environment. Blocking by IP can result in significant overblocking as all other (unrelated)
Web sites hosted on that server will also be blocked.
China uses IP blocking to obstruct access to at least three hundred IP addresses. This
blocking is done at the international gateway level affecting all users of the network regardless
of ISP. The IPs blocked among the two backbone providers, China Netcom and ChinaTelecom, are remarkably similar.
9
The ISP ETC-MC in Ethiopia uses IP blocking to block, among other sites, Google’s Blogspot blogging service. This results in all Blogspot blogs being blocked in Ethiopia. Pakistan
implements IP blocking at the international gateway level. In addition to blocking the IP for
Blogspot, they also block Yahoo’s hosting service, which results in major overblocking. For
example, in targeting www.balochvoice.com they are actually blocking more than 52,000 other
Web sites hosted on that same server.
DNS tampering is achieved by purposefully disrupting DNS servers, which resolve domain
names into IP addresses. Generally, each ISP maintains its own DNS server for use by its customers. To block access to particular Web sites, the DNS servers are configured to return the
wrong IP address. While this allows the blocking of specific domain names, it also can be easily circumvented by simple means such as accessing an IP address directly or by configuring
your computer to use a different DNS server.
In Vietnam, the ISP FPT configures DNS to not resolve certain domain names, as if the site
does not exist. The ISP Cybernet in Pakistan also uses this technique. The ISP Batelco in Bahrain uses this technique for some specific opposition sites. Batelco did not, however, completely remove the entry (the MX record for e-mail still remains). In India, the ISP BHARTI
resolves blocked sites to the invalid IP address 0.0.0.0 while the ISP VSNL resolves blocked
sites to the invalid IP address 1.2.3.4. The South Korean ISP, Hananet, uses this technique
but makes the blocked Web site resolve to 127.0.0.1. This is the IP address for the ‘‘localhost.’’ Another South Korean ISP, KORNET, makes blocked sites resolve to an ominous
police Web site. This represents an unusual case in which DNS tampering resolves to a blockpage.
10
Our tests revealed that there is often a combination of IP blocking and DNS tampering. It
may be a signal that countries are responding to the outcry concerning the overblocking associated with IP blocking and moving to the targeting of specific domain names with DNS tam14
Robert Faris and Nart Villeneuve
Précédent

- 31/467

Suivant