[Paper Review] Measuring Irregular Geographic Exposure on the Internet
This paper proposes a novel convex hull-based method to measure geographically irregular Internet routing exposure by defining 'normal' paths between source and destination countries based on population centers. Analyzing over 2.5 billion paths, it finds 44% of global Internet paths and 33% of Tor user paths unnecessarily expose traffic to at least one geographically irrelevant nation, rising to 49% when legal jurisdiction over ASes is considered, revealing systemic vulnerabilities to nation-state surveillance and control.
We examine the extent of needless traffic exposure by the routing infrastructure to nations geographically irrelevant to packet transmission. We quantify what countries are geographically logical to observe on a network path traveling between two nations through the use of convex hulls circumscribing major population centers. We then compare that to the nation states observed in over 2.5 billion measured paths. We examine both the entire geographic topology of the Internet and a subset of the topology that a Tor user would typically interact with. We find that 44% of paths across the entire geographic topology of the Internet and 33% of paths in the user experience subset unnecessarily expose traffic to one or more nations. Finally, we consider the scenario where countries exercise both legal and physical control over autonomous systems, gaining access to traffic outside of their geographic borders, but carried by organizations that fall under the AS's registered country's legal jurisdiction. At least 49% of paths in both measurements expose traffic to a geographically irrelevant country when considering both the physical and legal countries that a path traverses.
Motivation & Objective
- To quantify how often Internet routing exposes traffic to nation states that are geographically irrelevant to the source-destination path.
- To assess the extent to which nation states—through physical infrastructure control and legal jurisdiction over ASes—can act as path-based adversaries.
- To evaluate the impact of routing decisions on user privacy, especially for Tor users, by measuring exposure in a representative subset of real-world paths.
- To develop a method for defining 'geographically normal' paths using population-biased convex hulls around major population centers.
- To analyze how routing topology increases exposure to adversarial nation states beyond what is geographically necessary.
Proposed method
- Define 'geographically normal' paths using population-biased convex hulls that enclose major population centers between source and destination countries.
- Collect over 2.5 billion traceroute paths from CAIDA's Ark and RIPE Atlas measurement platforms.
- Classify each path’s exposure by comparing the actual countries traversed (physically and legally) to the set of countries within the convex hull.
- Distinguish between physical exposure (infrastructure location) and legal exposure (corporate governance jurisdiction) of Autonomous Systems (ASes).
- Compute a Path-Based Degree of Normality (DoN) metric to quantify the proportion of paths that are geographically logical.
- Analyze country-specific variations in exposure and identify nations most frequently involved in irregular routing.
Experimental results
Research questions
- RQ1To what extent does the Internet’s routing infrastructure expose traffic to nation states that lie outside the geographically logical path between sender and receiver?
- RQ2How does the combination of physical infrastructure location and legal jurisdiction over ASes increase the risk of nation-state surveillance beyond physical exposure alone?
- RQ3How does the exposure pattern differ between the global Internet topology and the subset of paths experienced by Tor users?
- RQ4Which countries are most frequently involved in geographically illogical routing paths, and how does this vary by origin and destination?
- RQ5Can routing policies be adjusted to reduce a nation’s exposure to path-based adversaries, and what would be the impact on DoN?
Key findings
- 44% of all-to-all Internet paths and 33% of Tor user experience paths physically expose traffic to at least one geographically irrelevant nation state.
- When legal jurisdiction over ASes is included, at least 49% of paths in both datasets expose traffic to at least one nation state that is not geographically necessary.
- The global Path-Based Degree of Normality (DoN) for physical exposure is 0.565 across the entire Internet and 0.632 for the user experience subset.
- The DoN for legal exposure is 0.712 for the full topology and 0.674 for the user experience subset, indicating that legal jurisdiction increases exposure risk.
- For more than half of the countries studied, at least 80% of inbound paths involve exposure to unexpected nation states, highlighting systemic geographic irregularity.
- The combined physical and legal DoN for the entire Internet is 0.519, and for user paths it is exactly 0.500, indicating that on average, paths are only slightly more than half geographically logical.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.