capability of the organization that requests the filtering—where they have access to, the people against whom they can enforce their wishes, and how much they are willing to spend. Other considerations include the number of acceptable errors, whether the filtering should be
overt or covert, and how reliable it is (both against ordinary users and those who wish to
bypass it). The next section discusses these trade-offs, but first we describe a range of mechanisms available to implement a filtering regime.
Here, we discuss only how access is blocked once the list of resources to be blocked is
established. Building this list is a considerable challenge and a common weakness in
deployed systems. Not only does the huge number of Web sites make building a comprehensive list of prohibited content difficult, but as content moves and Web sites change their IP
addresses, keeping this list up-to-date requires a lot of effort. Moreover, if the operator of the
site wishes to interfere with the blocking, the site could be moved more rapidly than it would
be otherwise.
TCP/IP Header Filtering
An IP packet consists of a header followed by the data the packet carries (the payload).
Routers must inspect the packet header, as this is where the destination IP address is
located. To prevent targeted hosts being accessed, routers can be configured to drop packets destined for IP addresses on a blacklist. However, each host may provide multiple services, such as hosting both Web sites and e-mail servers. Blocking based solely on IP
addresses will make all services on each blacklisted host inaccessible.
Slightly more precise blocking can be achieved by additionally blacklisting the port number,
which is also in the TCP/IP header. Common applications on the Internet have characteristic
port numbers, allowing routers to make a crude guess as to the service being accessed.
Thus, to block just the Web traffic to a site, a censor might block only packets destined for
port 80 (the normal port for Web servers).
Figure 3.2 shows where this type of blocking may be applied. Note that when the blocking
is performed, only the IP address is inspected, which is why multiple domain names that
share the same IP address will be blocked, even if only one is prohibited.
TCP/IP Content Filtering
TCP/IP header filtering can only block communication on the basis of where packets are
going to or coming from, not what they contain. This can be a problem if it is impossible to
establish the full list of IP addresses containing prohibited content, or if some IP address contains enough noninfringing content to make it unjustifiable to totally block all communication
with it. There is a finer-grained control possible: the content of packets can be inspected for
banned keywords.
As routers do not normally examine packet content but just packet headers, extra equipment may be needed. Typical hardware may be unable to react fast enough to block the
infringing packets, so other means to block the information must be used instead. As packets
Tools and Technology of Internet Filtering
59
overt or covert, and how reliable it is (both against ordinary users and those who wish to
bypass it). The next section discusses these trade-offs, but first we describe a range of mechanisms available to implement a filtering regime.
Here, we discuss only how access is blocked once the list of resources to be blocked is
established. Building this list is a considerable challenge and a common weakness in
deployed systems. Not only does the huge number of Web sites make building a comprehensive list of prohibited content difficult, but as content moves and Web sites change their IP
addresses, keeping this list up-to-date requires a lot of effort. Moreover, if the operator of the
site wishes to interfere with the blocking, the site could be moved more rapidly than it would
be otherwise.
TCP/IP Header Filtering
An IP packet consists of a header followed by the data the packet carries (the payload).
Routers must inspect the packet header, as this is where the destination IP address is
located. To prevent targeted hosts being accessed, routers can be configured to drop packets destined for IP addresses on a blacklist. However, each host may provide multiple services, such as hosting both Web sites and e-mail servers. Blocking based solely on IP
addresses will make all services on each blacklisted host inaccessible.
Slightly more precise blocking can be achieved by additionally blacklisting the port number,
which is also in the TCP/IP header. Common applications on the Internet have characteristic
port numbers, allowing routers to make a crude guess as to the service being accessed.
Thus, to block just the Web traffic to a site, a censor might block only packets destined for
port 80 (the normal port for Web servers).
Figure 3.2 shows where this type of blocking may be applied. Note that when the blocking
is performed, only the IP address is inspected, which is why multiple domain names that
share the same IP address will be blocked, even if only one is prohibited.
TCP/IP Content Filtering
TCP/IP header filtering can only block communication on the basis of where packets are
going to or coming from, not what they contain. This can be a problem if it is impossible to
establish the full list of IP addresses containing prohibited content, or if some IP address contains enough noninfringing content to make it unjustifiable to totally block all communication
with it. There is a finer-grained control possible: the content of packets can be inspected for
banned keywords.
As routers do not normally examine packet content but just packet headers, extra equipment may be needed. Typical hardware may be unable to react fast enough to block the
infringing packets, so other means to block the information must be used instead. As packets
Tools and Technology of Internet Filtering
59
