TCP/IP content filtering requires inspecting the payload of the IP packet, which is not ordinarily done by routers. Additional hardware may be required, which, for the data rates found
on high-speed Internet links, would be expensive. A cheaper option, which reduces reliability
but would considerably decrease cost, is for the filter to examine IP packets as they pass,
rather than stopping them for the duration of the examination. Now the filtering equipment is
not a bottleneck and may be slower, at the cost of missing some packets. When an infringement of policy is detected, the filtering hardware could send a message to both ends of the
connection, requesting that they terminate.
DNS tampering is also very inexpensive as recursive resolvers need not respond particularly rapidly and existing configuration options in DNS servers can be used to implement
filtering.
HTTP proxies require connections to be built by reassembling the constituent packets—
which requires substantial resources, thereby making this option expensive. Hybrid HTTP
proxies are more complex to set up, but once this is done, they are only slightly more expensive than IP filtering despite their much higher versatility. This is because the expensive
stage—the HTTP proxy—receives only a small proportion of the traffic, and so need not be
particularly powerful.
The cost of Denial-of-Service attacks is difficult to quantify as the scale required depends
on how capable the target server is and how fast its Internet connection is. Also, it will likely
be illegal to mount this attack, at least on the territory of another country. Legality also affects
surveillance, domain deregistration, and server takedown; while easy to do, these mechanisms require adequate legal or extra-legal provisions before ISPs will perform them.
Insertion of False Information
If access to a prohibited Web site is blocked, depending on the mechanism, the user experience will vary. For TCP/IP header and content filtering and Denial of Service it will appear as if
there has been an error, which may be desirable if the filtering is intended to be covert. The
other options, DNS tampering, proxy and hybrid proxy, domain deregistration, and server
takedown all give the option of displaying replacement content. This could be a notification
that the site is blocked, to be open about the filtering regime, or it could be a spoofed error
message, to be covert. Also, it could be false information, pretending to be from the authors
of the content, but actually from somewhere else.
Strategic and Tactical Considerations
It can be useful to compare filtering for censorship with filtering for other purposes. Wiretapping systems, firewalls, and intrusion detection systems share many of the same attributes
and problems. In general, such systems may be strategic or tactical. A country may collect strategic communications intelligence by intercepting all traffic with a hostile country
regardless of its type, source, or destination using a mechanism such as a tap into a cable. It
Tools and Technology of Internet Filtering
69
Précédent

- 86/467

Suivant