Analyzing the Great Firewall of China Over Space and Time

Analyzing the Great Firewall of China Over Space and Time
复制标题

DOI:
10.1515/popets-2015-0005
复制
发表时间:
2015-04
影响因子:
--
通讯作者:
Roya Ensafi;Philipp Winter;A. Mueen;Jedidiah R. Crandall
Roya Ensafi;Philipp Winter;A. Mueen;Jedidiah R. Crandall
中科院分区:
--
文献类型:
--
作者:
Roya Ensafi;Philipp Winter;A. Mueen;Jedidiah R. Crandall

文献摘要

被引文献

相似文献

一个国家级的防火墙,俗称“中国防火长城”,实施许多不同类型的审查和内容过滤,以控制中国的互联网流量。过去的工作表明,防火墙偶尔会失败。换句话说,有时中国的客户端能够访问中国以外的黑名单服务器。这一现象尚未得到描述,因为在中国不可能找到一个庞大的、地理位置多样化的客户群来测试连通性。在本文中,我们克服了这一挑战,通过使用一种混合空闲扫描技术,能够测量远程客户端和任意服务器之间的连接,这两者都不是在研究人员进行测量的控制下。除了混合空闲扫描之外,我们还在Linux内核的SYN backlog中提出并使用了一种新的侧通道。我们表明,这两种技术是实用的,通过测量的Tor网络,这是已知的被封锁在中国的可达性。我们的测量结果显示,防火墙故障发生在整个国家没有任何明显的地理模式。我们给出了一些证据,路由起着一定的作用,但其他因素(如GFW如何维护其IP/端口对阻止)也可能是重要的。
Abstract A nation-scale firewall, colloquially referred to as the “Great Firewall of China,” implements many different types of censorship and content filtering to control China’s Internet traffic. Past work has shown that the firewall occasionally fails. In other words, sometimes clients in China are able to reach blacklisted servers outside of China. This phenomenon has not yet been characterized because it is infeasible to find a large and geographically diverse set of clients in China from which to test connectivity. In this paper, we overcome this challenge by using a hybrid idle scan technique that is able to measure connectivity between a remote client and an arbitrary server, neither of which are under the control of the researcher performing measurements. In addition to hybrid idle scans, we present and employ a novel side channel in the Linux kernel’s SYN backlog. We show that both techniques are practical by measuring the reachability of the Tor network which is known to be blocked in China. Our measurements reveal that failures in the firewall occur throughout the entire country without any conspicuous geographical patterns.We give some evidence that routing plays a role, but other factors (such as how the GFW maintains its list of IP/port pairs to block) may also be important.