managed on a per-country basis by mandating that all ISPs look up domain names through
the government-run DNS server.
Server takedown must be done by the ISP hosting the server and domain deregistration by
the registry maintaining the domain use by the Web site. This will usually be a country toplevel domain and so be controlled by a government. The physical location of the server need
not correspond to the country code used.
Denial-of-Service attacks are the most versatile in terms of location, in that the attacker may
be anywhere and an effective attack will prevent access from anywhere.
Finally, social influence is most effectively applied by the country that can impose legal
sanctions on the people who are infringing the restrictions, be that people accessing banned
Web sites or people publishing banned content.
Error Rate
All the mechanisms suffer from the possibility of errors that may be of two kinds: ‘‘false
positives’’—where sites that were not intended to be blocked are inaccessible, and ‘‘false
negatives’’—where sites are accessible despite the intention that they be blocked. There is
commonly a trade-off between these two properties, which are also known as overblocking
and underblocking. The trade-off between false positives and false negatives is a pervasive
issue in security engineering, appearing in applications from biometric authentication to electronic warfare. The Receiver Operating Characteristic (ROC) is the term given to the curve that
maps the trade-off between false negative and false positive. Tweaking a parameter typically
moves the operating point of the system along the curve; for example, one may obtain fewer
false negatives but at the cost of more false positives. In general, the way to improve this
trade-off is to devise more precise ways of discriminating between desired and undesired
results. This will, in general, shift the ROC curve, so that false negatives and false positives
may be reduced at the same time.
TCP/IP header filtering is comparatively crude and must block an entire IP address or address range, which may host multiple Web sites and other services. Taking into account the
port number makes the discrimination more precise in that it might limit the blocking to only
Web traffic, but this still will often include several hundred Web sites.
5 Server takedown makes
the discrimination less precise, in that it will also make all content on the server inaccessible
(including content not served over the Web at all).
DNS tampering and domain deregistration will allow individual Web sites to be blocked but,
with the exception of e-mail, which may be handled differently at the DNS level, all services on
that domain will be made inaccessible. Both may be more precise than packet header filtering, as multiple servers may be hosted on one machine, and blacklisting that machine may
take down many Web sites other than the target site.
TCP/IP content filtering allows particular keywords to be filtered, allowing individual Web
pages to be blocked. It does run the risk of missing keywords that are split over multiple packets, but this would be unusual for standard Web browsers.
66
Steven J. Murdoch and Ross Anderson
the government-run DNS server.
Server takedown must be done by the ISP hosting the server and domain deregistration by
the registry maintaining the domain use by the Web site. This will usually be a country toplevel domain and so be controlled by a government. The physical location of the server need
not correspond to the country code used.
Denial-of-Service attacks are the most versatile in terms of location, in that the attacker may
be anywhere and an effective attack will prevent access from anywhere.
Finally, social influence is most effectively applied by the country that can impose legal
sanctions on the people who are infringing the restrictions, be that people accessing banned
Web sites or people publishing banned content.
Error Rate
All the mechanisms suffer from the possibility of errors that may be of two kinds: ‘‘false
positives’’—where sites that were not intended to be blocked are inaccessible, and ‘‘false
negatives’’—where sites are accessible despite the intention that they be blocked. There is
commonly a trade-off between these two properties, which are also known as overblocking
and underblocking. The trade-off between false positives and false negatives is a pervasive
issue in security engineering, appearing in applications from biometric authentication to electronic warfare. The Receiver Operating Characteristic (ROC) is the term given to the curve that
maps the trade-off between false negative and false positive. Tweaking a parameter typically
moves the operating point of the system along the curve; for example, one may obtain fewer
false negatives but at the cost of more false positives. In general, the way to improve this
trade-off is to devise more precise ways of discriminating between desired and undesired
results. This will, in general, shift the ROC curve, so that false negatives and false positives
may be reduced at the same time.
TCP/IP header filtering is comparatively crude and must block an entire IP address or address range, which may host multiple Web sites and other services. Taking into account the
port number makes the discrimination more precise in that it might limit the blocking to only
Web traffic, but this still will often include several hundred Web sites.
5 Server takedown makes
the discrimination less precise, in that it will also make all content on the server inaccessible
(including content not served over the Web at all).
DNS tampering and domain deregistration will allow individual Web sites to be blocked but,
with the exception of e-mail, which may be handled differently at the DNS level, all services on
that domain will be made inaccessible. Both may be more precise than packet header filtering, as multiple servers may be hosted on one machine, and blacklisting that machine may
take down many Web sites other than the target site.
TCP/IP content filtering allows particular keywords to be filtered, allowing individual Web
pages to be blocked. It does run the risk of missing keywords that are split over multiple packets, but this would be unusual for standard Web browsers.
66
Steven J. Murdoch and Ross Anderson
