HTTP proxy and hybrid approaches give the greatest flexibility, allowing blocking both by
full Web page URL and by Web page content.
Denial-of-Service attacks are the most crude of the options discussed. Since they normally
make sites inaccessible by saturating the network infrastructure, rather than the server itself,
many servers could be blocked unintentionally, and perhaps the entire ISP hosting the prohibited content.
Surveillance and the threat of legal measures can be effective, as the human element
allows much greater subtlety. Even if the authorities have not discovered a site that should
be blocked, self-censorship will still discourage users from attempting to access it. However,
such measures are also likely to result in overblocking by creating a climate of fear.
Detectability
Given adequate access to computers that are being blocked from accessing certain Web
sites, it is possible to reliably detect most of the mechanisms already discussed. Mechanisms
at the server side are more difficult. For example, although the server being blocked can detect Denial of Service, it may be difficult to differentiate from a legitimate ‘‘flash crowd.’’ Similarly, a server that has been taken down, or whose domain name has been deregistered for
reasons of blocking, appears the same as one that has suffered a hardware failure or DNS
misconfiguration.
Surveillance is extremely difficult to detect technically if it has been competently implemented. However, the results of surveillance (arrests or warnings) are often made visible in
order to deter future infringement of the rules. So it may be possible to infer the existence of
surveillance, but law enforcement agencies may choose to hide precisely how they obtained
the information used for targeting.
Circumventability
Although the mechanisms discussed will block access to prohibited resources to users who
have configured their computers in a normal way, the protections may be circumvented. However, the effort and skills required vary.
DNS filtering is comparatively easy to bypass by the user selecting an alternative recursive resolver. This type of circumvention may be made more difficult by blocking access to
external DNS servers, but doing so would be disruptive to normal activities and could also
be bypassed.
TCP/IP header filtering, HTTP proxies, and hybrid proxies may all be fooled by redirecting
traffic through an open proxy server. Such servers may be set up accidentally by computer
users who misconfigure their own computers. Alternatively, a proxy could be specifically
designed for circumventing Internet filtering. Here, the main challenge is to discover an open
proxy as many are shut down rapidly due to spammers abusing them, or blocked by organizations that realize they are being used for circumvention.
Tools and Technology of Internet Filtering
67
full Web page URL and by Web page content.
Denial-of-Service attacks are the most crude of the options discussed. Since they normally
make sites inaccessible by saturating the network infrastructure, rather than the server itself,
many servers could be blocked unintentionally, and perhaps the entire ISP hosting the prohibited content.
Surveillance and the threat of legal measures can be effective, as the human element
allows much greater subtlety. Even if the authorities have not discovered a site that should
be blocked, self-censorship will still discourage users from attempting to access it. However,
such measures are also likely to result in overblocking by creating a climate of fear.
Detectability
Given adequate access to computers that are being blocked from accessing certain Web
sites, it is possible to reliably detect most of the mechanisms already discussed. Mechanisms
at the server side are more difficult. For example, although the server being blocked can detect Denial of Service, it may be difficult to differentiate from a legitimate ‘‘flash crowd.’’ Similarly, a server that has been taken down, or whose domain name has been deregistered for
reasons of blocking, appears the same as one that has suffered a hardware failure or DNS
misconfiguration.
Surveillance is extremely difficult to detect technically if it has been competently implemented. However, the results of surveillance (arrests or warnings) are often made visible in
order to deter future infringement of the rules. So it may be possible to infer the existence of
surveillance, but law enforcement agencies may choose to hide precisely how they obtained
the information used for targeting.
Circumventability
Although the mechanisms discussed will block access to prohibited resources to users who
have configured their computers in a normal way, the protections may be circumvented. However, the effort and skills required vary.
DNS filtering is comparatively easy to bypass by the user selecting an alternative recursive resolver. This type of circumvention may be made more difficult by blocking access to
external DNS servers, but doing so would be disruptive to normal activities and could also
be bypassed.
TCP/IP header filtering, HTTP proxies, and hybrid proxies may all be fooled by redirecting
traffic through an open proxy server. Such servers may be set up accidentally by computer
users who misconfigure their own computers. Alternatively, a proxy could be specifically
designed for circumventing Internet filtering. Here, the main challenge is to discover an open
proxy as many are shut down rapidly due to spammers abusing them, or blocked by organizations that realize they are being used for circumvention.
Tools and Technology of Internet Filtering
67
