3
Tools and Technology of Internet Filtering
Steven J. Murdoch and Ross Anderson
Internet Background
TCP/IP is the unifying set of conventions that allows different computers to communicate over
the Internet. The basic unit of information transferred over the Internet is the Internet protocol
(IP) packet. All Internet communication—whether downloading Web pages, sending e-mail, or
transferring files—is achieved by connecting to another computer, splitting the data into packets, and sending them on their way to the intended destination.
Specialized computers known as routers are responsible for directing packets appropriately. Each router is connected to several communication links, which may be cables (fiberoptic or electrical), short-range wireless, or even satellite. On receiving a packet, the router
makes a decision of which outgoing link is most appropriate for getting that packet to its ultimate destination. The approach of encapsulating all communication in a common format (IP)
is one of the major factors for the Internet’s success. It allows different networks, with disparate underlying structures, to communicate by hiding this nonuniformity from application
developers.
Routers identify computers (hosts) on the Internet by their IP address, which might look like
192.0.2.166. Since such numbers are hard to remember, the domain name system (DNS)
allows mnemonic names (domain names) to be associated with IP addresses. A host wishing
to make a connection first looks up the IP address for a given name, then sends packets to
this IP address. For example, the Uniform Resource Locator (URL) www.example.com/
page.html contains the domain name ‘‘www.example.com.’’ The computer that performs
the domain-name-to-IP-address lookup is known as a DNS resolver, and is commonly operated by the Internet service provider (ISP)—the company providing the user with Internet
access.
During connection establishment, there are several different ways in which the process can
be interrupted in order to perform censorship or some other filtering function. The next section
describes how a number of the most relevant filtering mechanisms operate. Each mechanism
has its own strengths and weaknesses and these are discussed later. Many of the blocking
mechanisms are effective for a range of different Internet applications, but in this chapter we
concentrate on access to the Web, as this is the current focus of Internet filtering efforts.
Tools and Technology of Internet Filtering
Steven J. Murdoch and Ross Anderson
Internet Background
TCP/IP is the unifying set of conventions that allows different computers to communicate over
the Internet. The basic unit of information transferred over the Internet is the Internet protocol
(IP) packet. All Internet communication—whether downloading Web pages, sending e-mail, or
transferring files—is achieved by connecting to another computer, splitting the data into packets, and sending them on their way to the intended destination.
Specialized computers known as routers are responsible for directing packets appropriately. Each router is connected to several communication links, which may be cables (fiberoptic or electrical), short-range wireless, or even satellite. On receiving a packet, the router
makes a decision of which outgoing link is most appropriate for getting that packet to its ultimate destination. The approach of encapsulating all communication in a common format (IP)
is one of the major factors for the Internet’s success. It allows different networks, with disparate underlying structures, to communicate by hiding this nonuniformity from application
developers.
Routers identify computers (hosts) on the Internet by their IP address, which might look like
192.0.2.166. Since such numbers are hard to remember, the domain name system (DNS)
allows mnemonic names (domain names) to be associated with IP addresses. A host wishing
to make a connection first looks up the IP address for a given name, then sends packets to
this IP address. For example, the Uniform Resource Locator (URL) www.example.com/
page.html contains the domain name ‘‘www.example.com.’’ The computer that performs
the domain-name-to-IP-address lookup is known as a DNS resolver, and is commonly operated by the Internet service provider (ISP)—the company providing the user with Internet
access.
During connection establishment, there are several different ways in which the process can
be interrupted in order to perform censorship or some other filtering function. The next section
describes how a number of the most relevant filtering mechanisms operate. Each mechanism
has its own strengths and weaknesses and these are discussed later. Many of the blocking
mechanisms are effective for a range of different Internet applications, but in this chapter we
concentrate on access to the Web, as this is the current focus of Internet filtering efforts.
