In-depth analysis of the Great Firewall of China

In-depth analysis of the Great Firewall of China
复制标题

深入解析中国防火墙

DOI:
--
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
C. Tang
C. Tang
中科院分区:
--
文献类型:
--
作者:
C. Tang

文献摘要

被引文献

相似文献

由金盾工程创建的中国防火长城(GFW)是世界上最大的审查系统的支柱。作为一个路径上系统,GFW可以监控流量并注入额外的数据包,但不能阻止传输中的数据包到达其目的地。它使用三种主要技术来实现审查:首先,它检查中国和世界其他地区之间的所有互联网流量,然后通过向两端注入伪造的TCP重置数据包来终止包含审查内容的连接。随着HTTPS的出现,它不能被GFW解密,TCP HTTPS近年来的使用越来越少。其次,GFW阻止通过所有中国ISP的网关路由器访问特定的IP地址。第三,它使用DNS篡改来返回虚假的IP地址,以响应对被阻止域的DNS查询。这会影响对国内和国外DNS服务的查询。IP拦截和DNS篡改一起是GFW的面包和黄油,有效地切断了对被封锁网站的所有访问。但是,这种严厉的方法不可避免地会导致过度审查,并对流经中国和无辜网站的国际网络流量造成附带损害。用户可以绕过GFW的三种主要方式是使用VPN,代理和Tor。然而,GFW可以使用深度数据包检测和机器学习来关闭可疑的VPN或代理隧道,并使用主动探测系统来关闭Tor网桥中继。到目前为止,很少有商业VPN服务和使用可插拔传输的最新Tor协议是可行的方法。
Created by the Golden Shield Project, the Great Firewall of China (GFW) is the backbone of world’s largest system of censorship. As an on-path system, the GFW can monitor traffic and inject additional packets, but cannot stop in-flight packets from reaching its destination. It achieves censorship using three main techniques: First, it inspects all Internet traffic between China and the rest of the world, then terminate connections containing censored content by injecting forged TCP Reset packets to both ends. With the advent of HTTPS, which cannot be decrypted by the GFW, TCP RST has seen fewer use in recent years. Second, the GFW blocks access to specific IP addresses through the gateway routers of all Chinese ISPs. Third, it uses DNS tampering to return false IP addresses in response to DNS queries to blocked domains. This affects queries to both domestic and foreign DNS services. IP blocking and DNS tampering together are the bread and butter of GFW, effectively cutting off all access to blocked websites. But, such draconian methods inevitably cause over-censoring and collateral damage to international web traffic flowing through China and innocent websites. The three main ways a user can bypass the GFW are the use of VPNs, Proxies, and Tor. However, GFW can use deep packet inspection and machine learning to shutdown suspected VPN or proxy tunnels, and use an active probing system to shutdown Tor bridge relays. As of today, few commercial VPN services and the latest Tor protocols using Pluggable Transports are viable approaches.