In-depth analysis of the Great Firewall of China
In-depth analysis of the Great Firewall of China
复制标题
深入解析中国防火墙
DOI:
--
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
C. Tang
中科院分区:
文献类型:
--
作者:
C. Tang
Created by the Golden Shield Project, the Great Firewall of China (GFW) is the backbone of world’s largest system of censorship. As an on-path system, the GFW can monitor traffic and inject additional packets, but cannot stop in-flight packets from reaching its destination. It achieves censorship using three main techniques: First, it inspects all Internet traffic between China and the rest of the world, then terminate connections containing censored content by injecting forged TCP Reset packets to both ends. With the advent of HTTPS, which cannot be decrypted by the GFW, TCP RST has seen fewer use in recent years. Second, the GFW blocks access to specific IP addresses through the gateway routers of all Chinese ISPs. Third, it uses DNS tampering to return false IP addresses in response to DNS queries to blocked domains. This affects queries to both domestic and foreign DNS services. IP blocking and DNS tampering together are the bread and butter of GFW, effectively cutting off all access to blocked websites. But, such draconian methods inevitably cause over-censoring and collateral damage to international web traffic flowing through China and innocent websites. The three main ways a user can bypass the GFW are the use of VPNs, Proxies, and Tor. However, GFW can use deep packet inspection and machine learning to shutdown suspected VPN or proxy tunnels, and use an active probing system to shutdown Tor bridge relays. As of today, few commercial VPN services and the latest Tor protocols using Pluggable Transports are viable approaches.